NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
69330 | CVE-2005-3692 | Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail attachments. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
4050 | CVE-2008-4194 | The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a "dangling pointer bug." | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
69586 | CVE-2005-3948 | Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters. | 2 | 5 | Medium | 2017-01-03 | 2008-10-03 | View | |
4306 | CVE-2008-4483 | Directory traversal vulnerability in index.php in Crux Gallery 1.32 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
5074 | CVE-2008-5296 | Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-03 | 2008-12-02 | View |
Page 16039 of 17672, showing 5 records out of 88360 total, starting on record 80191, ending on 80195