NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54958 | CVE-2007-2795 | Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon. | 2 | 9 | High | 2017-01-07 | 2009-01-28 | View | |
| 4606 | CVE-2008-4792 | The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values. | 2 | 6 | Medium | 2017-01-03 | 2009-01-28 | View | |
| 5632 | CVE-2008-5901 | iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 2049 | CVE-2008-2115 | Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 3329 | CVE-2008-3448 | Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 2589 of 17672, showing 5 records out of 88360 total, starting on record 12941, ending on 12945