NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2299 | CVE-2008-2380 | SQL injection vulnerability in authpgsqllib.c in Courier-Authlib before 0.62.0, when a non-Latin locale Postgres database is used, allows remote attackers to execute arbitrary SQL commands via query parameters containing apostrophes. | 2 | 5.1 | Medium | 2017-01-03 | 2009-03-20 | View | |
67835 | CVE-2005-2128 | QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value. | 2 | 5 | Medium | 2017-01-03 | 2008-09-10 | View | |
3067 | CVE-2008-3184 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue can be leveraged to execute arbitrary PHP code. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
3579 | CVE-2008-3714 | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
69883 | CVE-2005-4285 | Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 17501 of 17672, showing 5 records out of 88360 total, starting on record 87501, ending on 87505