NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88311 | CVE-2016-6793 | The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.7 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object. | 2017-07-18 | 2017-07-17 | View | ||||
56311 | CVE-2007-4180 | ** DISPUTED ** Directory traversal vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to read arbitrary local files via a .. (dot dot) in the file parameter. NOTE: CVE and a reliable third party dispute this vulnerability because the code uses a fixed argument when invoking fputs, which cannot be used to read files. | 2 | 5 | Medium | 2017-06-23 | 2017-06-21 | View | |
66040 | CVE-2005-0277 | Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66552 | CVE-2005-0802 | Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
66808 | CVE-2005-1059 | Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View |
Page 17387 of 17672, showing 5 records out of 88360 total, starting on record 86931, ending on 86935