NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67800 | CVE-2005-2091 | IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling." | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
68568 | CVE-2005-2893 | Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), which is directly injected into a file that is later executed upon login. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
70872 | CVE-2004-0425 | Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
71128 | CVE-2004-0701 | Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View | |
71384 | CVE-2004-0982 | Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View |
Page 17283 of 17672, showing 5 records out of 88360 total, starting on record 86411, ending on 86415