NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72222 | CVE-2004-1844 | Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 6942 | CVE-2008-7211 | CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windows Vista, does not create a Functional Device Object (FDO) to prevent user-moade access to the Physical Device Object (PDO), which allows local users to gain SYSTEM privileges via a crafted IRP request that dereferences a NULL FsContext pointer. | 2 | 6.9 | Medium | 2017-01-03 | 2009-09-14 | View | |
| 72478 | CVE-2004-2101 | The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 7198 | CVE-2011-0063 | The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences. NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049. | 2 | 5 | Medium | 2017-01-07 | 2011-09-21 | View | |
| 72734 | CVE-2004-2357 | The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, which allows remote attackers to read or modify the backend database. | 2 | 6.4 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 2047 of 17672, showing 5 records out of 88360 total, starting on record 10231, ending on 10235