NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71164 | CVE-2004-0737 | Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (10) mod2, or (11) mod3 parameters. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71420 | CVE-2004-1019 | The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
71676 | CVE-2004-1296 | The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
71932 | CVE-2004-1553 | SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
72188 | CVE-2004-1810 | The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17651 of 17672, showing 5 records out of 88360 total, starting on record 88251, ending on 88255