NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
69807 | CVE-2005-4209 | WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability. | 2 | 4.3 | Medium | 2017-01-03 | 2009-10-31 | View | |
76957 | CVE-2000-0716 | WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user"s email. | 2 | 2.6 | Low | 2017-01-05 | 2016-09-16 | View | |
6444 | CVE-2008-6713 | World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block to TCP port 48000, which triggers a NULL pointer dereference. | 2 | 5 | Medium | 2017-01-03 | 2009-04-13 | View | |
5505 | CVE-2008-5765 | WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for data/usr.txt. | 2 | 5 | Medium | 2017-01-03 | 2008-12-31 | View | |
81121 | CVE-2002-2170 | Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View |
Page 160 of 17672, showing 5 records out of 88360 total, starting on record 796, ending on 800