NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88086 | CVE-2017-7666 | Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks. | 2017-07-18 | 2017-07-17 | View | ||||
88342 | CVE-2017-5246 | Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluated by any other authenticated user who views the attacker's display name. | 2017-07-18 | 2017-07-18 | View | ||||
66071 | CVE-2005-0308 | Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
66839 | CVE-2005-1090 | Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files. | 2 | 6.4 | Medium | 2017-07-18 | 2017-07-10 | View | |
68119 | CVE-2005-2428 | Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 16428 of 17672, showing 5 records out of 88360 total, starting on record 82136, ending on 82140