NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88236 | CVE-2017-9874 | IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000007822. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
59820 | CVE-2006-1098 | ** DISPUTED ** Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem. | 2 | 7.5 | High | 2017-07-18 | 2017-07-11 | View | |
66989 | CVE-2005-1243 | Directory traversal vulnerability in the third party tool from SafeStone, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
67245 | CVE-2005-1507 | Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
67757 | CVE-2005-2048 | Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp. NOTE: vectors 1 and 3 were later reported to affect version 3.0. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 17221 of 17672, showing 5 records out of 88360 total, starting on record 86101, ending on 86105