NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56672  CVE-2007-4552  SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not.    7.5  High  2017-01-07  2008-11-15  View
57184  CVE-2007-5101  ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local users to gain privileges.    7.2  High  2017-01-07  2008-11-15  View
57696  CVE-2007-5633  Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, allows local users to read or write arbitrary MSRs, and gain privileges and load unsigned drivers, via the (1) IOCTL_RDMSR 0x9C402438 and (2) IOCTL_WRMSR 0x9C40243C IOCTLs to Devicespeedfan, as demonstrated by an IOCTL_WRMSR action on MSR_LSTAR.    7.2  High  2017-01-07  2008-11-15  View
52321  CVE-2007-0089  jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.    7.5  High  2017-01-07  2008-11-15  View
53345  CVE-2007-1138  Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.    Medium  2017-01-07  2008-11-15  View

Page 2377 of 17672, showing 5 records out of 88360 total, starting on record 11881, ending on 11885

Actions