NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 3957 | CVE-2008-4099 | PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-19 | View | |
| 3958 | CVE-2008-4100 | GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: the vendor reports that this is intended behavior and is compatible with the product"s intended role in a trusted environment. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-19 | View | |
| 3982 | CVE-2008-4126 | PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4099. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-19 | View | |
| 69641 | CVE-2005-4003 | Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. NOTE: the original disclosure was specifically only for an XSS issue, but the CVE description was for SQL injection. Since the original disclosure, SQL injection vectors have been reported. This CVE might be REJECTed or significantly altered pending additional information. | 2 | 7.5 | High | 2017-01-03 | 2008-09-20 | View | |
| 69901 | CVE-2005-4303 | SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter. | 2 | 7.5 | High | 2017-01-03 | 2008-09-20 | View |
Page 2165 of 17672, showing 5 records out of 88360 total, starting on record 10821, ending on 10825