NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72378 | CVE-2004-2001 | ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View | |
73146 | CVE-2004-2769 | Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the "Display hidden files" option is enabled, via the (1) MLSD or (2) MLST commands. | 2 | 4 | Medium | 2016-12-20 | 2010-07-06 | View | |
58810 | CVE-2006-0070 | ** DISPUTED ** Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
59066 | CVE-2006-0327 | TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
59322 | CVE-2006-0587 | Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arbitrary code via unspecified vectors involving a crafted link to a crafted file. | 2 | 6.5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17261 of 17672, showing 5 records out of 88360 total, starting on record 86301, ending on 86305