NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88304 | CVE-2016-4000 | Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object. | 2 | 7.5 | High | 2017-07-18 | 2017-07-17 | View | |
33264 | CVE-2014-5640 | The CM Backup -Restore,Cloud,Photo (aka com.ijinshan.kbackup) application 1.1.0.135 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.4 | Medium | 2017-07-18 | 2017-07-11 | View | |
55280 | CVE-2007-3126 | Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237. | 2 | 5 | Medium | 2017-05-27 | 2017-05-23 | View | |
66033 | CVE-2005-0270 | Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
66545 | CVE-2005-0795 | HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17330 of 17672, showing 5 records out of 88360 total, starting on record 86646, ending on 86650