NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6974 | CVE-2008-7243 | Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords via manager/index.php. NOTE: due to the lack of details, it is not clear whether this is related to CVE-2008-5941. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-18 | View | |
| 72510 | CVE-2004-2133 | Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72766 | CVE-2004-2389 | Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 7742 | CVE-2011-0701 | wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter. | 2 | 4 | Medium | 2017-01-07 | 2011-04-20 | View | |
| 7998 | CVE-2011-1008 | Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging. | 2 | 4 | Medium | 2017-01-07 | 2011-03-10 | View |
Page 2235 of 17672, showing 5 records out of 88360 total, starting on record 11171, ending on 11175