NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72386 | CVE-2004-2009 | NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72387 | CVE-2004-2010 | PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72388 | CVE-2004-2011 | msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI. | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
| 72389 | CVE-2004-2012 | The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
| 72390 | CVE-2004-2013 | Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View |
Page 2030 of 17672, showing 5 records out of 88360 total, starting on record 10146, ending on 10150