NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5035 | CVE-2008-5252 | Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors. | 2 | 5.8 | Medium | 2017-01-03 | 2009-10-14 | View | |
5034 | CVE-2008-5250 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and uploads are enabled, or an SVG scripting browser is used and SVG uploads are enabled, allows remote authenticated users to inject arbitrary web script or HTML by editing a wiki page. | 2 | 3.5 | Low | 2017-01-03 | 2009-10-14 | View | |
5033 | CVE-2008-5249 | Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.0 through 1.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-10-14 | View | |
5032 | CVE-2008-5248 | xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators." | 2 | 4.3 | Medium | 2017-01-03 | 2009-11-24 | View | |
5031 | CVE-2008-5247 | The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codec_data_length) value as a divisor, which allow remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero value. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View |
Page 16666 of 17672, showing 5 records out of 88360 total, starting on record 83326, ending on 83330