NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
74464 | CVE-2003-1394 | CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
225 | CVE-2008-0240 | /idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection." | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
481 | CVE-2008-0506 | include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-11 | View | |
66017 | CVE-2005-0253 | Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
737 | CVE-2008-0766 | Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a "Receive data file" LPD command. NOTE: some of these details are obtained from third party information. | 2 | 10 | High | 2017-01-03 | 2011-03-07 | View |
Page 15892 of 17672, showing 5 records out of 88360 total, starting on record 79456, ending on 79460