NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52310 | CVE-2007-0078 | BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
69154 | CVE-2005-3493 | Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server"s UDP port. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
76412 | CVE-2000-0169 | Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes "?&". | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
23360 | CVE-2015-0943 | Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream. | 2 | 5.8 | Medium | 2017-01-19 | 2015-08-31 | View | |
27582 | CVE-2015-6742 | Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability types and different affected versions. | 2 | 6.5 | Medium | 2017-01-19 | 2015-08-31 | View |
Page 16172 of 17672, showing 5 records out of 88360 total, starting on record 80856, ending on 80860