NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2596  CVE-2008-2698  Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) id, or (3) category parameter.    4.3  Medium  2017-01-03  2009-01-29  View
5412  CVE-2008-5670  Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.    6.8  Medium  2017-01-03  2009-01-29  View
5668  CVE-2008-5937  AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values.    7.8  High  2017-01-03  2009-01-29  View
47652  CVE-2009-0320  Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."    Medium  2017-01-07  2009-01-29  View
4389  CVE-2008-4573  SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter.    7.5  High  2017-01-03  2009-01-29  View

Page 2605 of 17672, showing 5 records out of 88360 total, starting on record 13021, ending on 13025

Actions