NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69673 | CVE-2005-4035 | Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 4393 | CVE-2008-4577 | The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions. | 2 | 6.4 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 69929 | CVE-2005-4331 | SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 4649 | CVE-2008-4837 | Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; and Microsoft Works 8 allow remote attackers to execute arbitrary code via a crafted Word document that contains a malformed table property, which triggers memory corruption, aka "Word Memory Corruption Vulnerability." | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View | |
| 70185 | CVE-2005-4596 | Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-20 | View |
Page 2472 of 17672, showing 5 records out of 88360 total, starting on record 12356, ending on 12360