NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55288 | CVE-2007-3134 | Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using "Approve Comments." | 2 | 4.3 | Medium | 2017-01-07 | 2012-10-30 | View | |
55544 | CVE-2007-3392 | Wireshark before 0.99.6 allows remote attackers to cause a denial of service via malformed (1) SSL or (2) MMS packets that trigger an infinite loop. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View | |
55800 | CVE-2007-3650 | myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error messages. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
56056 | CVE-2007-3920 | GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069. | 2 | 6.2 | Medium | 2017-01-07 | 2010-08-21 | View | |
56312 | CVE-2007-4181 | ** DISPUTED ** PHP remote file inclusion vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: A reliable third party disputes this vulnerability because the applicable include is within a function that does not receive the dir parameter from an HTTP request. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 17424 of 17672, showing 5 records out of 88360 total, starting on record 87116, ending on 87120