NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72851  CVE-2004-2474  SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.    7.5  High  2017-07-18  2017-07-10  View
72852  CVE-2004-2475  Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.    4.3  Medium  2017-07-18  2017-07-10  View
72853  CVE-2004-2476  Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.    2.6  Low  2017-07-18  2017-07-10  View
72854  CVE-2004-2477  DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in devicephysicalmemory with the original SDT found in ntoskrnl.exe.    2.1  Low  2017-07-18  2017-07-10  View
72855  CVE-2004-2478  Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.    7.5  High  2017-07-18  2017-07-10  View

Page 2123 of 17672, showing 5 records out of 88360 total, starting on record 10611, ending on 10615

Actions