NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69926 | CVE-2005-4328 | Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 4646 | CVE-2008-4832 | rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. NOTE: this issue exists because of a race condition in an incorrect fix for CVE-2008-3524. NOTE: exploitation may require an unusual scenario in which rc.sysinit is executed other than at boot time. | 2 | 6.9 | Medium | 2017-01-03 | 2012-10-30 | View | |
| 70182 | CVE-2005-4593 | PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 4902 | CVE-2008-5118 | Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection." | 2 | 4.3 | Medium | 2017-01-03 | 2012-10-30 | View | |
| 70438 | CVE-2005-4849 | Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 2586 of 17672, showing 5 records out of 88360 total, starting on record 12926, ending on 12930