NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
69934 | CVE-2005-4336 | Cross-site scripting (XSS) vulnerability in ProjectForum 4.7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) fwd parameter in admin/adminsignin.html and (2) originalpageid parameter in admin/newpage.html associated with a group. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
4654 | CVE-2008-4865 | Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated using a malicious --db-command options. NOTE: the severity of this issue has been disputed, but CVE is including this issue because execution of a program from an untrusted directory is a common scenario. | 2 | 7.2 | High | 2017-01-03 | 2009-03-30 | View | |
70190 | CVE-2005-4601 | The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
4910 | CVE-2008-5126 | Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-11-20 | View | |
70446 | CVE-2005-4857 | eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error". | 2 | 4 | Medium | 2017-01-03 | 2015-07-28 | View |
Page 1926 of 17672, showing 5 records out of 88360 total, starting on record 9626, ending on 9630