NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66728 | CVE-2005-0979 | Multiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted values in a profile file, as demonstrated using a long SysName field. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
66984 | CVE-2005-1238 | By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
67240 | CVE-2005-1502 | Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) searchstring parameter to search_list.php or the (2) secondgroup or (3) maingroup parameters to item_list.php. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
68520 | CVE-2005-2845 | Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
69288 | CVE-2005-3650 | The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode. | 2 | 9.3 | High | 2017-07-18 | 2017-07-10 | View |
Page 16769 of 17672, showing 5 records out of 88360 total, starting on record 83841, ending on 83845