NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 71491 | CVE-2004-1099 | Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
| 71747 | CVE-2004-1368 | ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script. | 2 | 7.8 | High | 2017-07-18 | 2017-07-10 | View | |
| 72003 | CVE-2004-1624 | Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe). | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
| 6723 | CVE-2008-6992 | GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
| 72259 | CVE-2004-1881 | SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 2123 of 17672, showing 5 records out of 88360 total, starting on record 10611, ending on 10615