NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
64578  CVE-2006-6017  WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.    Medium  2016-12-20  2008-09-05  View
64834  CVE-2006-6273  sp_index.php in Simple PHP Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid dir parameter, which reveals the path in an error message.    7.5  High  2016-12-20  2008-09-05  View
65603  CVE-2006-7060  cindex.php in Scriptsez.net E-Dating System allows remote attackers to obtain the full path via an invalid id parameter in a dologin action, which leaks the path in an error message.    Medium  2016-12-20  2008-09-05  View
579  CVE-2008-0604  The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions.    6.8  Medium  2017-01-03  2008-09-05  View
66371  CVE-2005-0620  Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.    2.1  Low  2017-01-03  2008-09-05  View

Page 16399 of 17672, showing 5 records out of 88360 total, starting on record 81991, ending on 81995

Actions