NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65879 | CVE-2005-0099 | The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View | |
855 | CVE-2008-0884 | The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file permissions, leading to a change to world-writable permissions for the /etc/pam.d/system-auth-ac file, which allows local users to gain privileges by modifying this file. | 2 | 6.9 | Medium | 2017-01-03 | 2008-09-05 | View | |
66391 | CVE-2005-0640 | Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods. | 2 | 4.6 | Medium | 2017-01-03 | 2008-09-05 | View | |
67159 | CVE-2005-1420 | Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space). | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
67927 | CVE-2005-2225 | Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has been reported that Gaim is also affected, so this may be an issue in the protocol or MSN servers. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 16528 of 17672, showing 5 records out of 88360 total, starting on record 82636, ending on 82640