NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1514 | CVE-2008-1570 | Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569. | 2 | 6.9 | Medium | 2017-01-03 | 2008-12-01 | View | |
67050 | CVE-2005-1311 | Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
67306 | CVE-2005-1579 | Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
67562 | CVE-2005-1838 | Multiple cross-site scripting vulnerabilities in castnewPost.asp in Liberum Help Desk 0.97.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Email, (2) Title, or (3) Description fields. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
67818 | CVE-2005-2109 | wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 16888 of 17672, showing 5 records out of 88360 total, starting on record 84436, ending on 84440