NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72437 | CVE-2004-2060 | ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
7157 | CVE-2011-0018 | The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or (2) From e-mail address in an OMP request to the Greenbone Security Assistant (GSA). | 2 | 9 | High | 2017-01-07 | 2011-02-05 | View | |
72693 | CVE-2004-2316 | Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via a GET request containing an MS-DOS device name such as COM1. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
7413 | CVE-2011-0314 | Heap-based buffer overflow in IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 allows remote authenticated users to execute arbitrary code or cause a denial of service (queue manager crash) by inserting an invalid message into the queue. | 2 | 6.5 | Medium | 2017-01-07 | 2011-01-20 | View | |
72949 | CVE-2004-2572 | AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as () or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 16937 of 17672, showing 5 records out of 88360 total, starting on record 84681, ending on 84685