NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
74634  CVE-2003-1564  libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."    9.3  High  2017-01-03  2008-10-24  View
139  CVE-2008-0149  TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.    Medium  2017-01-03  2008-09-05  View
395  CVE-2008-0417  CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user"s password store via newlines that are not properly handled when the user saves a password.    4.3  Medium  2017-01-03  2011-03-07  View
651  CVE-2008-0678  SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a page action.    6.8  Medium  2017-01-03  2009-08-25  View
66187  CVE-2005-0429  Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.    Medium  2017-01-03  2016-10-17  View

Page 2777 of 17672, showing 5 records out of 88360 total, starting on record 13881, ending on 13885

Actions