NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 20577 | CVE-2016-5253 | The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link. | 2 | 4.7 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 50906 | CVE-2009-3720 | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625. | 2 | 5 | Medium | 2017-01-07 | 2016-08-22 | View | |
| 63560 | CVE-2006-4952 | The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter. | 2 | 7.5 | High | 2016-12-20 | 2016-11-28 | View | |
| 8514 | CVE-2011-1584 | The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allows remote authenticated users to upload and execute arbitrary PHP code via the media_path or media_file parameter. NOTE: some of these details are obtained from third party information. | 2 | 6.5 | Medium | 2017-01-07 | 2012-04-27 | View | |
| 4295 | CVE-2008-4472 | The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View |
Page 2847 of 17672, showing 5 records out of 88360 total, starting on record 14231, ending on 14235