NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
79940 | CVE-2002-0944 | Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
79939 | CVE-2002-0943 | MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb. | 2 | 6.4 | Medium | 2017-01-05 | 2008-09-05 | View | |
79938 | CVE-2002-0942 | Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long arguments to the extended stored procedures (1) xp_logattach_StartProf, (2) xp_logattach_setport, or (3) xp_logattach. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
79937 | CVE-2002-0941 | The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
79936 | CVE-2002-0940 | domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only). | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-10 | View |
Page 16619 of 17672, showing 5 records out of 88360 total, starting on record 83091, ending on 83095