NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66754 | CVE-2005-1005 | ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstrated via a direct request to adminshop/index.php with hex-encoded .. sequences in the ftoedit parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
67266 | CVE-2005-1528 | Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
67778 | CVE-2005-2069 | pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
68546 | CVE-2005-2871 | Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
69314 | CVE-2005-3676 | SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the file parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 1723 of 17672, showing 5 records out of 88360 total, starting on record 8611, ending on 8615