NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67920 | CVE-2005-2218 | The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden devices available to attackers, who can then bypass restrictions on a jailed process. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
68176 | CVE-2005-2485 | Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
68432 | CVE-2005-2744 | Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file. | 2 | 5.1 | Medium | 2017-07-18 | 2017-07-10 | View | |
69456 | CVE-2005-3818 | Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
70736 | CVE-2004-0285 | PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 16770 of 17672, showing 5 records out of 88360 total, starting on record 83846, ending on 83850