NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71108 | CVE-2004-0681 | Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09 allow remote attackers to execute web script as other users via the message parameter. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
71620 | CVE-2004-1231 | Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequences in a DCC connection with a CTCP packet that contains a 1 as the type and a 4 as the subtype. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
72132 | CVE-2004-1753 | The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs. | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
72388 | CVE-2004-2011 | msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI. | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
72644 | CVE-2004-2267 | Cross-site scripting (XSS) vulnerability in Ansel 2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via the album name. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17202 of 17672, showing 5 records out of 88360 total, starting on record 86006, ending on 86010