NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66984 | CVE-2005-1238 | By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
67240 | CVE-2005-1502 | Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) searchstring parameter to search_list.php or the (2) secondgroup or (3) maingroup parameters to item_list.php. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
68520 | CVE-2005-2845 | Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
69288 | CVE-2005-3650 | The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode. | 2 | 9.3 | High | 2017-07-18 | 2017-07-10 | View | |
70568 | CVE-2004-0104 | Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 17195 of 17672, showing 5 records out of 88360 total, starting on record 85971, ending on 85975