NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2596 | CVE-2008-2698 | Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) id, or (3) category parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5412 | CVE-2008-5670 | Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5668 | CVE-2008-5937 | AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values. | 2 | 7.8 | High | 2017-01-03 | 2009-01-29 | View | |
| 47652 | CVE-2009-0320 | Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack." | 2 | 4 | Medium | 2017-01-07 | 2009-01-29 | View | |
| 4389 | CVE-2008-4573 | SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View |
Page 2605 of 17672, showing 5 records out of 88360 total, starting on record 13021, ending on 13025