NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3056  CVE-2008-3172  Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attackers to perform a session fixation attack and hijack a user"s HTTP session, aka "Cross-Site Cooking."    6.8  Medium  2017-01-03  2008-09-10  View
68592  CVE-2005-2926  Stack-based buffer overflow in (1) backupsh and (2) authsh in SCO Openserver 5.0.7 allows local users to execute arbitrary code via a long HOME environment variable.    4.6  Medium  2017-01-03  2011-03-07  View
3312  CVE-2008-3431  The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \.VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.    7.2  High  2017-01-03  2011-03-07  View
68848  CVE-2005-3186  Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.    7.5  High  2017-01-03  2011-03-07  View
3568  CVE-2008-3703  The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows remote attackers to execute arbitrary code via requests to the service socket that create "snapshots schedules" registry values specifying future command execution. NOTE: this issue exists because of an incomplete fix for CVE-2007-2279.    10  High  2017-01-03  2011-03-07  View

Page 16711 of 17672, showing 5 records out of 88360 total, starting on record 83551, ending on 83555

Actions