NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53611 | CVE-2007-1427 | Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
54123 | CVE-2007-1953 | Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
56171 | CVE-2007-4040 | Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
56427 | CVE-2007-4302 | Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users to defeat system call interposition and possibly gain privileges or bypass auditing. | 2 | 6.2 | Medium | 2017-01-07 | 2008-09-05 | View | |
57707 | CVE-2007-5644 | Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorized sort operations and other activities. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View |
Page 16676 of 17672, showing 5 records out of 88360 total, starting on record 83376, ending on 83380