NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6467 | CVE-2008-6736 | Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product"s security documentation. | 2 | 6.4 | Medium | 2017-01-03 | 2009-04-22 | View | |
| 6723 | CVE-2008-6992 | GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
| 6979 | CVE-2008-7248 | Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain. | 2 | 6.8 | Medium | 2017-01-03 | 2012-07-06 | View | |
| 73283 | CVE-2003-0136 | psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-10 | View | |
| 73539 | CVE-2003-0409 | Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request. | 2 | 10 | High | 2017-01-03 | 2016-10-17 | View |
Page 2120 of 17672, showing 5 records out of 88360 total, starting on record 10596, ending on 10600