NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67854 | CVE-2005-2150 | Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
68110 | CVE-2005-2419 | B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request to firmwarecfg. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
70670 | CVE-2004-0217 | The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log. | 2 | 3.7 | Low | 2017-07-18 | 2017-07-10 | View | |
70926 | CVE-2004-0490 | cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
71182 | CVE-2004-0755 | The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View |
Page 16376 of 17672, showing 5 records out of 88360 total, starting on record 81876, ending on 81880