NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80651 | CVE-2002-1699 | SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
84491 | CVE-2017-3479 | Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Private Banking. CVSS 3.0 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L). | 2 | 5.5 | Medium | 2017-07-18 | 2017-07-10 | View | |
65804 | CVE-2005-0010 | Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
67852 | CVE-2005-2148 | Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
68108 | CVE-2005-2417 | Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 300 of 17672, showing 5 records out of 88360 total, starting on record 1496, ending on 1500