NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56021 | CVE-2007-3880 | Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog. | 2 | 7.2 | High | 2017-01-07 | 2011-03-07 | View | |
57813 | CVE-2007-5761 | The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \.NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value. | 2 | 7.2 | High | 2017-01-07 | 2011-03-07 | View | |
58069 | CVE-2007-6048 | IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related. | 2 | 10 | High | 2017-01-07 | 2011-03-07 | View | |
58325 | CVE-2007-6330 | Meridian Prolog Manager 2007, and 7.5 and earlier, sends all usernames and passwords to the client in a (1) cleartext or (2) weakly encrypted format to support client-side login authentication, which makes it easier for remote attackers to obtain database access by capturing credentials via a man-in-the-middle attack. | 2 | 10 | High | 2017-01-07 | 2008-11-15 | View | |
58581 | CVE-2007-6586 | SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View |
Page 16171 of 17672, showing 5 records out of 88360 total, starting on record 80851, ending on 80855