NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2593  CVE-2008-2695  Directory traversal vulnerability in entry.php in phpInv 0.8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.    7.5  High  2017-01-03  2009-04-14  View
68129  CVE-2005-2438  Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.    4.3  Medium  2017-07-18  2017-07-10  View
2849  CVE-2008-2955  Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_slplink_process_msg function.    4.3  Medium  2017-01-03  2013-11-02  View
68385  CVE-2005-2696  IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document properties in the NAB, or (3) a direct query to the Domino LDAP server, a different vulnerability than CVE-2005-2428.    Medium  2017-01-03  2016-10-17  View
3105  CVE-2008-3222  Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.    6.8  Medium  2017-01-03  2009-08-19  View

Page 2243 of 17672, showing 5 records out of 88360 total, starting on record 11211, ending on 11215

Actions