NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56032 | CVE-2007-3891 | Unspecified vulnerability in Windows Vista Weather Gadgets in Windows Vista allows remote attackers to execute arbitrary code via crafted HTML attributes. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
56288 | CVE-2007-4157 | PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication cookie only requires the password hash, not the cleartext version. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
56544 | CVE-2007-4419 | Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area. | 2 | 9.3 | High | 2017-01-07 | 2008-11-15 | View | |
56800 | CVE-2007-4680 | CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
57056 | CVE-2007-4966 | SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View |
Page 15788 of 17672, showing 5 records out of 88360 total, starting on record 78936, ending on 78940