NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67720 | CVE-2005-2008 | Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null). | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
64304 | CVE-2006-5729 | Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users. | 2 | 6.5 | Medium | 2016-12-20 | 2008-09-05 | View | |
73019 | CVE-2004-2642 | Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender. | 2 | 6.4 | Medium | 2016-12-20 | 2016-10-11 | View | |
5604 | CVE-2008-5873 | Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
80797 | CVE-2002-1846 | Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 17630 of 17672, showing 5 records out of 88360 total, starting on record 88146, ending on 88150