NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 4930 | CVE-2008-5146 | add-accession-numbers in ctn 3.0.6 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/accession temporary file. | 2 | 6.9 | Medium | 2017-01-03 | 2008-11-18 | View | |
| 70466 | CVE-2005-4877 | Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.3.0 Beta 2 allows remote attackers to inject arbitrary web script or HTML via Javascript events in the username parameter, a different vulnerability than CVE-2005-4876. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-10 | View | |
| 5186 | CVE-2008-5413 | PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2009-0434. | 2 | 5 | Medium | 2017-01-03 | 2011-08-23 | View | |
| 5442 | CVE-2008-5700 | libata in the Linux kernel before 2.6.27.9 does not set minimum timeouts for SG_IO requests, which allows local users to cause a denial of service (Programmed I/O mode on drives) via multiple simultaneous invocations of an unspecified test program. | 2 | 1.9 | Low | 2017-01-03 | 2012-03-19 | View | |
| 5698 | CVE-2008-5967 | admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root. | 2 | 7.5 | High | 2017-01-03 | 2009-02-05 | View |
Page 2110 of 17672, showing 5 records out of 88360 total, starting on record 10546, ending on 10550