NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 67718 | CVE-2005-2006 | JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 2438 | CVE-2008-2530 | Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter to (a) frontend/news.php, the (2) id parameter to (b) events3.php and (c) videos2.php in frontend/, the (3) y parameter to (d) frontend/events2.php, and the (4) ser parameter to (e) frontend/fotos2.php. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 2694 | CVE-2008-2800 | Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest. | 2 | 4.3 | Medium | 2017-01-03 | 2012-11-26 | View | |
| 68230 | CVE-2005-2541 | Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges. | 2 | 10 | High | 2017-01-03 | 2016-10-17 | View | |
| 2950 | CVE-2008-3060 | V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-03 | 2008-10-23 | View |
Page 2734 of 17672, showing 5 records out of 88360 total, starting on record 13666, ending on 13670