NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 56381 | CVE-2007-4252 | Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveToFile method, a different vulnerability than CVE-2007-3633. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 56637 | CVE-2007-4514 | Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors. | 2 | 5 | Medium | 2017-01-07 | 2009-04-18 | View | |
| 56893 | CVE-2007-4780 | Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57661 | CVE-2007-5596 | The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
| 58173 | CVE-2007-6170 | SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments. | 2 | 6.5 | Medium | 2017-01-07 | 2011-03-07 | View |
Page 2227 of 17672, showing 5 records out of 88360 total, starting on record 11131, ending on 11135