NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52019 | CVE-2009-4904 | article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action. | 2 | 5 | Medium | 2017-01-07 | 2012-11-05 | View | |
52787 | CVE-2007-0563 | Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
53299 | CVE-2007-1091 | Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
53555 | CVE-2007-1370 | Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities. | 2 | 6.2 | Medium | 2017-01-07 | 2011-03-07 | View | |
54067 | CVE-2007-1897 | SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable. | 2 | 6.5 | Medium | 2017-01-07 | 2011-08-05 | View |
Page 1863 of 17672, showing 5 records out of 88360 total, starting on record 9311, ending on 9315