NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4505 | CVE-2008-4691 | Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
4504 | CVE-2008-4690 | lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler. | 2 | 10 | High | 2017-01-03 | 2010-08-21 | View | |
4503 | CVE-2008-4689 | Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions. | 2 | 7.5 | High | 2017-01-03 | 2009-01-28 | View | |
4502 | CVE-2008-4688 | core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue"s title and status via a request with a modified issue number. | 2 | 5 | Medium | 2017-01-03 | 2009-02-10 | View | |
4501 | CVE-2008-4687 | manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php. | 2 | 9 | High | 2017-01-03 | 2009-08-19 | View |
Page 16772 of 17672, showing 5 records out of 88360 total, starting on record 83856, ending on 83860