NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70434  CVE-2005-4845  The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control"s CLSID, which is not intended for use within Internet Explorer.    Medium  2017-01-03  2009-08-28  View
5154  CVE-2008-5376  editcomment in crip 3.7 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.tag.tmp temporary file.    6.9  Medium  2017-01-03  2008-12-09  View
5410  CVE-2008-5668  Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section.    4.3  Medium  2017-01-03  2009-01-29  View
5666  CVE-2008-5935  Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for database/facto.mdb. NOTE: some of these details are obtained from third party information.    Medium  2017-01-03  2009-01-29  View
5922  CVE-2008-6191  Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries.    2.1  Low  2017-01-03  2009-07-15  View

Page 1820 of 17672, showing 5 records out of 88360 total, starting on record 9096, ending on 9100

Actions