NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4605 | CVE-2008-4791 | The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors. | 2 | 6 | Medium | 2017-01-03 | 2009-02-05 | View | |
4604 | CVE-2008-4790 | The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors. | 2 | 6 | Medium | 2017-01-03 | 2009-02-05 | View | |
4603 | CVE-2008-4789 | The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error." | 2 | 6 | Medium | 2017-01-03 | 2009-02-05 | View | |
4602 | CVE-2008-4788 | Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, which allows remote attackers to spoof the address bar via a URL with a domain name that differs from an important domain name only in these characters, as demonstrated by using exam%A9ple.com to spoof example.com, aka MSRC ticket MSRC7900. | 2 | 5 | Medium | 2017-01-03 | 2009-07-22 | View | |
4601 | CVE-2008-4787 | Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC ticket MSRC7899, a related issue to CVE-2003-1025. | 2 | 5.8 | Medium | 2017-01-03 | 2009-09-08 | View |
Page 16752 of 17672, showing 5 records out of 88360 total, starting on record 83756, ending on 83760