NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35864 | CVE-2014-9044 | Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack. | 2 | 5 | Medium | 2017-01-19 | 2015-02-05 | View | |
37687 | CVE-2013-1495 | asr in Oracle Auto Service Request in Oracle Support Tools before 4.3.2 allows local users to modify arbitrary files via a symlink attack on a predictable filename in /tmp. | 2 | 6.9 | Medium | 2017-01-18 | 2013-10-10 | View | |
61492 | CVE-2006-2807 | ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp. | 2 | 10 | High | 2016-12-20 | 2008-09-05 | View | |
48510 | CVE-2009-1223 | aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb. | 2 | 5 | Medium | 2017-01-07 | 2009-04-18 | View | |
5352 | CVE-2008-5603 | ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for news.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 16240 of 17672, showing 5 records out of 88360 total, starting on record 81196, ending on 81200