NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67595 | CVE-2005-1877 | Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
67851 | CVE-2005-2147 | Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-05 | View | |
3339 | CVE-2008-3458 | Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
72715 | CVE-2004-2338 | OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
74507 | CVE-2003-1437 | BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View |
Page 16074 of 17672, showing 5 records out of 88360 total, starting on record 80366, ending on 80370