NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 3695 | CVE-2008-3833 | The generic_file_splice_write function in fs/splice.c in the Linux kernel before 2.6.19 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by splicing into an inode in order to create an executable file in a setgid directory, a different vulnerability than CVE-2008-4210. | 2 | 4.9 | Medium | 2017-01-03 | 2013-08-21 | View | |
| 69231 | CVE-2005-3571 | PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 3951 | CVE-2008-4093 | SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-20 | View | |
| 69487 | CVE-2005-3849 | Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 4207 | CVE-2008-4380 | The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, related to the filter for configuration properties and "/x" characters. | 2 | 7.8 | High | 2017-01-03 | 2009-08-19 | View |
Page 2528 of 17672, showing 5 records out of 88360 total, starting on record 12636, ending on 12640