NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56385  CVE-2007-4256  Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter.    Medium  2017-01-07  2008-11-15  View
57153  CVE-2007-5065  PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.    7.5  High  2017-01-07  2008-11-15  View
57921  CVE-2007-5894  ** DISPUTED ** The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating " The "length" variable is only uninitialized if "auth_type" is neither the "KERBEROS_V4" nor "GSSAPI"; this condition cannot occur in the unmodified source code."    9.3  High  2017-01-07  2008-11-15  View
55362  CVE-2007-3209  Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensitive information by sniffing the network.    7.8  High  2017-01-07  2008-11-15  View
56386  CVE-2007-4257  Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary code via (1) a .spr file (single player replay file) containing a long user name or (2) a .ply file containing a long number plate string, different vectors than CVE-2007-4140.    6.8  Medium  2017-01-07  2008-11-15  View

Page 2349 of 17672, showing 5 records out of 88360 total, starting on record 11741, ending on 11745

Actions