NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6446 | CVE-2008-6715 | Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) homeadmin/adminhome.php and (2) homeadmin/signinform.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-13 | View | |
6702 | CVE-2008-6971 | The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation codes, which allows remote attackers to modify passwords of other users and gain privileges. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
6958 | CVE-2008-7227 | PartialBufferOutputStream2 in GeoServer before 1.6.1 and 1.7.0-beta1 attempts to flush buffer contents even when it is handling an "in memory buffer," which prevents the reporting of a service exception, with unknown impact and attack vectors. | 2 | 5 | Medium | 2017-01-03 | 2009-09-15 | View | |
73262 | CVE-2003-0115 | Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233. | 2 | 7.5 | High | 2017-01-03 | 2008-09-10 | View | |
73518 | CVE-2003-0388 | pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name. | 2 | 4.6 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 1928 of 17672, showing 5 records out of 88360 total, starting on record 9636, ending on 9640