NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
13622  CVE-2010-2135  Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.    7.5  High  2017-01-18  2010-06-03  View
79158  CVE-2002-0142  CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 characters long and ends in a series of . (dot) characters.    7.5  High  2017-01-05  2016-10-17  View
14134  CVE-2010-2685  siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attackers to bypass intended restrictions and add administrative users via a direct request.    7.5  High  2017-01-18  2016-10-06  View
79670  CVE-2002-0670  The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.    7.5  High  2017-01-05  2008-09-05  View
80182  CVE-2002-1196  editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.    7.5  High  2017-01-05  2016-10-17  View

Page 2549 of 17672, showing 5 records out of 88360 total, starting on record 12741, ending on 12745

Actions