NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6924 | CVE-2008-7193 | PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading the PHPKITSID parameter from the HTTP Referer and using it in a request to (1) modify the user profile via upload_files/include.php or (2) create a new administrator via upload_files/pk/include.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-10 | View | |
73228 | CVE-2003-0081 | Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
74508 | CVE-2003-1438 | Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
13 | CVE-2008-0013 | Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product"s configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0014. | 2 | 10 | High | 2017-01-03 | 2012-10-30 | View | |
269 | CVE-2008-0284 | Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments. | 2 | 4.3 | Medium | 2017-01-03 | 2009-09-15 | View |
Page 1618 of 17672, showing 5 records out of 88360 total, starting on record 8086, ending on 8090