NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72492 | CVE-2004-2115 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
72748 | CVE-2004-2371 | Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly check return values from certain functions, which allows remote attackers to cause a denial of service (hang) via packets that contain text strings with incorrect size values. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
74284 | CVE-2003-1212 | MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
9260 | CVE-2011-2481 | Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression. | 2 | 4.6 | Medium | 2017-05-27 | 2017-05-22 | View | |
75308 | CVE-1999-0656 | The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 15840 of 17672, showing 5 records out of 88360 total, starting on record 79196, ending on 79200