NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
65569  CVE-2006-7026  PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter, a different vector than CVE-2006-2149.    6.8  Medium  2016-12-20  2008-09-05  View
289  CVE-2008-0304  Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.    7.5  High  2017-01-03  2011-03-07  View
65825  CVE-2005-0040  Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.    4.3  Medium  2017-01-03  2016-10-17  View
545  CVE-2008-0570  The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.    Medium  2017-01-03  2011-03-07  View
66081  CVE-2005-0318  useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users" account information via a modified user parameter.    2.1  Low  2017-01-03  2016-10-17  View

Page 2590 of 17672, showing 5 records out of 88360 total, starting on record 12946, ending on 12950

Actions