NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 50371 | CVE-2009-3166 | token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. | 2 | 5 | Medium | 2017-01-07 | 2009-09-19 | View | |
| 4143 | CVE-2008-4315 | tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks. | 2 | 6.8 | Medium | 2017-01-03 | 2010-08-21 | View | |
| 68672 | CVE-2005-3008 | Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 69211 | CVE-2005-3551 | toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 4334 | CVE-2008-4511 | Todd Woolums ASP News Management, possibly 2.21, stores db/news.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 2498 of 17672, showing 5 records out of 88360 total, starting on record 12486, ending on 12490