NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4665  CVE-2008-4876  Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page.    4.3  Medium  2017-01-03  2011-03-07  View
70201  CVE-2005-4612  Multiple SQL injection vulnerabilities in VUBB alpha rc1 allow remote attackers to execute arbitrary SQL commands via the (1) f parameter to viewforum.php, (2) t parameter to viewtopic.php, and (3) view parameter to usercp.php.    7.5  High  2017-01-03  2008-09-20  View
4921  CVE-2008-5137  tkman in tkman 2.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/tkman##### or (2) /tmp/ll temporary file.    6.9  Medium  2017-01-03  2009-02-17  View
70457  CVE-2005-4868  Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain senstitive information, such as cleartext passwords, and cause a denial of service.    2.1  Low  2017-01-03  2016-10-17  View
5177  CVE-2008-5404  Insecure method vulnerability in the FlexCell.Grid ActiveX control in FlexCell.ocx 5.7.0.1 in FlexCell Grid ActiveX Component allows remote attackers to create and overwrite arbitrary files via the HttpDownloadFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    10  High  2017-01-03  2009-08-15  View

Page 2029 of 17672, showing 5 records out of 88360 total, starting on record 10141, ending on 10145

Actions