NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2076 | CVE-2008-2143 | Unspecified versions of Microsoft Outlook Web Access (OWA) use the Cache-Control: no-cache HTTP directive instead of no-store, which might cause web browsers that follow RFC-2616 to cache sensitive information. | 2 | 1.9 | Low | 2017-01-03 | 2008-09-05 | View | |
68380 | CVE-2005-2691 | includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
69404 | CVE-2005-3766 | Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers to access the pages by browsing uploaded files. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
70428 | CVE-2005-4839 | PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
72988 | CVE-2004-2611 | The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 16178 of 17672, showing 5 records out of 88360 total, starting on record 80886, ending on 80890