NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72851 | CVE-2004-2474 | SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72852 | CVE-2004-2475 | Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72853 | CVE-2004-2476 | Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source. | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
| 72854 | CVE-2004-2477 | DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in devicephysicalmemory with the original SDT found in ntoskrnl.exe. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
| 72855 | CVE-2004-2478 | Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 2123 of 17672, showing 5 records out of 88360 total, starting on record 10611, ending on 10615