NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72641  CVE-2004-2264  ** DISPUTED ** Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless there are plausible scenarios under which privilege boundaries could be crossed.    6.4  Medium  2017-07-18  2017-07-10  View
86079  CVE-2017-8769  ** DISPUTED ** Facebook WhatsApp Messenger 2.17.146 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expect file deletion to occur upon chat deletion, or who expect encryption (consistent with the application's use of an encrypted database to store chat text). NOTE: the vendor reportedly indicates that they do not consider these to be security issues because a user may legitimately want to preserve any file for use in other apps like the Google Photos gallery regardless of whether its associated chat is deleted.    Medium  2017-06-03  2017-05-31  View
59486  CVE-2006-0756  ** DISPUTED ** dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php.    Medium  2016-12-20  2011-03-07  View
59484  CVE-2006-0754  ** DISPUTED ** dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scripts in the db directory, which reveal the path in an error message. NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php.    Medium  2016-12-20  2011-03-07  View
58984  CVE-2006-0244  ** DISPUTED ** Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root.    Medium  2016-12-20  2011-03-07  View

Page 17598 of 17672, showing 5 records out of 88360 total, starting on record 87986, ending on 87990

Actions