NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66493 | CVE-2005-0743 | The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
66749 | CVE-2005-1000 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
70589 | CVE-2004-0125 | The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing table. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
70845 | CVE-2004-0397 | Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71101 | CVE-2004-0674 | Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17169 of 17672, showing 5 records out of 88360 total, starting on record 85841, ending on 85845