NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52310  CVE-2007-0078  BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb.    Medium  2017-01-07  2008-11-15  View
69154  CVE-2005-3493  Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server"s UDP port.    Medium  2017-01-03  2016-10-17  View
76412  CVE-2000-0169  Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes "?&".    7.5  High  2017-01-05  2008-09-10  View
23360  CVE-2015-0943  Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream.    5.8  Medium  2017-01-19  2015-08-31  View
27582  CVE-2015-6742  Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability types and different affected versions.    6.5  Medium  2017-01-19  2015-08-31  View

Page 16172 of 17672, showing 5 records out of 88360 total, starting on record 80856, ending on 80860

Actions