NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67595  CVE-2005-1877  Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter.    4.3  Medium  2017-01-03  2008-09-05  View
67851  CVE-2005-2147  Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.    6.4  Medium  2017-01-03  2008-09-05  View
3339  CVE-2008-3458  Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.    Medium  2017-01-03  2008-09-05  View
72715  CVE-2004-2338  OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.    7.5  High  2016-12-20  2008-09-05  View
74507  CVE-2003-1437  BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.    2.1  Low  2017-01-03  2008-09-05  View

Page 16074 of 17672, showing 5 records out of 88360 total, starting on record 80366, ending on 80370

Actions