NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54958  CVE-2007-2795  Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.    High  2017-01-07  2009-01-28  View
4606  CVE-2008-4792  The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.    Medium  2017-01-03  2009-01-28  View
5632  CVE-2008-5901  iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2009-01-29  View
2049  CVE-2008-2115  Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.    4.3  Medium  2017-01-03  2009-01-29  View
3329  CVE-2008-3448  Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.    4.3  Medium  2017-01-03  2009-01-29  View

Page 2589 of 17672, showing 5 records out of 88360 total, starting on record 12941, ending on 12945

Actions