NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
79052 | CVE-2002-0036 | Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
13772 | CVE-2010-2294 | Cross-site request forgery (CSRF) vulnerability in Plume CMS 1.2.4 and possibly earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-18 | 2010-06-18 | View | |
79308 | CVE-2002-0298 | ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
14284 | CVE-2010-2850 | Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter. | 2 | 6.8 | Medium | 2017-01-18 | 2010-07-26 | View | |
80076 | CVE-2002-1081 | The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 15831 of 17672, showing 5 records out of 88360 total, starting on record 79151, ending on 79155