NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70833 | CVE-2004-0385 | Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities." | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
71089 | CVE-2004-0662 | PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71601 | CVE-2004-1212 | Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71857 | CVE-2004-1478 | JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
72113 | CVE-2004-1734 | PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 17123 of 17672, showing 5 records out of 88360 total, starting on record 85611, ending on 85615