NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 68618 | CVE-2005-2954 | SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 68619 | CVE-2005-2955 | config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others. | 2 | 4.6 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 68620 | CVE-2005-2956 | ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 68621 | CVE-2005-2957 | Stack-based buffer overflow in AVIRA Desktop for Windows 1.00.00.68 with AVPACK32.DLL 6.31.0.3, when archive scanning is enabled, allows remote attackers to execute arbitrary code via a long filename in an ACE archive. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 68622 | CVE-2005-2958 | Multiple format string vulnerabilities in the GNOME Data Access library for GNOME2 (libgda2) 1.2.1 and earlier allow attackers to execute arbitrary code. | 2 | 7.5 | High | 2017-01-03 | 2010-04-02 | View |
Page 2748 of 17672, showing 5 records out of 88360 total, starting on record 13736, ending on 13740