NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70416 | CVE-2005-4827 | Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces. NOTE: this issue can be leveraged to conduct referer spoofing, HTTP Request Smuggling, and other attacks. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
5136 | CVE-2008-5358 | Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll. | 2 | 9.3 | High | 2017-01-03 | 2016-08-22 | View | |
5392 | CVE-2008-5650 | SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commands via the pwd parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-08-12 | View | |
5648 | CVE-2008-5917 | Cross-site scripting (XSS) vulnerability in the XSS filter (framework/Text_Filter/Filter/xss.php) in Horde Application Framework 3.2.2 and 3.3, when Internet Explorer is being used, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to style attributes. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-18 | View | |
5904 | CVE-2008-6173 | Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-05-14 | View |
Page 1652 of 17672, showing 5 records out of 88360 total, starting on record 8256, ending on 8260