NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56048 | CVE-2007-3910 | Cross-site scripting (XSS) vulnerability in Bandersnatch 0.4 allows remote attackers to inject arbitrary JavaScript via a Jabber resource name and possibly other data items, which are stored in conversation logs. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
56304 | CVE-2007-4173 | SQL injection vulnerability in duyuruoku.asp in Hunkaray Okul Portali 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-3080. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
56560 | CVE-2007-4435 | Multiple SQL injection vulnerabilities in TorrentTrader before 1.07 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) account-inbox.php, (2) account-settings.php, and possibly (3) backend/functions.php. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
56816 | CVE-2007-4696 | Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
57072 | CVE-2007-4983 | Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a .. (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call. | 2 | 10 | High | 2017-01-07 | 2011-03-07 | View |
Page 16760 of 17672, showing 5 records out of 88360 total, starting on record 83796, ending on 83800