NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70188 | CVE-2005-4599 | Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
4908 | CVE-2008-5124 | JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
70444 | CVE-2005-4855 | Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks. | 2 | 3.5 | Low | 2017-01-03 | 2015-07-28 | View | |
5164 | CVE-2008-5386 | Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vectors. | 2 | 6.9 | Medium | 2017-01-03 | 2008-12-17 | View | |
5420 | CVE-2008-5678 | Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (3) text.ini files. | 2 | 4 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 1908 of 17672, showing 5 records out of 88360 total, starting on record 9536, ending on 9540