NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71419 | CVE-2004-1018 | Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
6139 | CVE-2008-6408 | PHP remote file inclusion vulnerability in frame.php in ol"bookmarks manager 0.7.5 allows remote attackers to execute arbitrary PHP code via a URL in the framefile parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
71675 | CVE-2004-1295 | The slip_down function in slip.c for the uml_net program in uml-utilities 20030903, when uml_net is installed setuid root, does not verify whether the calling user has sufficient permission to disable an interface, which allows local users to cause a denial of service (network service disabled). | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
6395 | CVE-2008-6664 | action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values. | 2 | 7.5 | High | 2017-01-03 | 2009-04-08 | View | |
71931 | CVE-2004-1552 | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 16993 of 17672, showing 5 records out of 88360 total, starting on record 84961, ending on 84965