NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
1806  CVE-2008-1866  admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.    High  2017-01-03  2011-03-07  View
48398  CVE-2009-1088  Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as demonstrated using xalan://java.lang.Runtime.    High  2017-01-07  2009-10-05  View
54286  CVE-2007-2116  Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors, aka DB10. NOTE: as of 20070424, Oracle has not disputed claims that these are buffer overflows in kkzi.o for the SYS.DBMS_SNAP_INTERNAL package using the (1) SNAP_OWNER or (2) SNAP_NAME parameters.    High  2017-01-07  2016-04-29  View
75536  CVE-1999-0886  The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.    High  2017-01-05  2008-09-09  View
40208  CVE-2013-4633  Huawei Seco Versatile Security Manager (VSM) before V200R002C00SPC300 allows remote authenticated users to gain privileges via a certain change to a group configuration setting.    High  2017-01-18  2013-06-21  View

Page 16380 of 17672, showing 5 records out of 88360 total, starting on record 81896, ending on 81900

Actions