NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1806 | CVE-2008-1866 | admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request. | 2 | 9 | High | 2017-01-03 | 2011-03-07 | View | |
48398 | CVE-2009-1088 | Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as demonstrated using xalan://java.lang.Runtime. | 2 | 9 | High | 2017-01-07 | 2009-10-05 | View | |
54286 | CVE-2007-2116 | Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors, aka DB10. NOTE: as of 20070424, Oracle has not disputed claims that these are buffer overflows in kkzi.o for the SYS.DBMS_SNAP_INTERNAL package using the (1) SNAP_OWNER or (2) SNAP_NAME parameters. | 2 | 9 | High | 2017-01-07 | 2016-04-29 | View | |
75536 | CVE-1999-0886 | The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. | 2 | 9 | High | 2017-01-05 | 2008-09-09 | View | |
40208 | CVE-2013-4633 | Huawei Seco Versatile Security Manager (VSM) before V200R002C00SPC300 allows remote authenticated users to gain privileges via a certain change to a group configuration setting. | 2 | 9 | High | 2017-01-18 | 2013-06-21 | View |
Page 16380 of 17672, showing 5 records out of 88360 total, starting on record 81896, ending on 81900