NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80446 | CVE-2002-1493 | Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag. | 2 | 4.3 | Medium | 2017-01-05 | 2008-09-05 | View | |
80958 | CVE-2002-2007 | The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
81214 | CVE-2002-2263 | The installation program for HP-UX Visualize Conference B.11.00.11 running on HP-UX 11.00 and 11.11 installs /etc/dt and its subdirecties with insecure permissions, which allows local users to read or write arbitrary files. | 2 | 6.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
53566 | CVE-2007-1381 | The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow. | 2 | 7.6 | High | 2017-01-07 | 2008-09-05 | View | |
54334 | CVE-2007-2164 | Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 16373 of 17672, showing 5 records out of 88360 total, starting on record 81861, ending on 81865