NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67868 | CVE-2005-2164 | SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
2588 | CVE-2008-2690 | Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter to (1) kb.php, (2) login.php, (3) index.php, (4) contact_view.php, and (5) contact.php in pub/, different vectors than CVE-2008-2689. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 9.3 | High | 2017-01-03 | 2009-04-08 | View | |
2844 | CVE-2008-2950 | The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document. | 2 | 7.5 | High | 2017-01-03 | 2012-11-26 | View | |
68380 | CVE-2005-2691 | includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
3100 | CVE-2008-3217 | PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-10 | View |
Page 1760 of 17672, showing 5 records out of 88360 total, starting on record 8796, ending on 8800