NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56403  CVE-2007-4275  Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db2licm and (4) db2pd.    6.9  Medium  2017-01-07  2011-03-07  View
56659  CVE-2007-4539  The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.    Medium  2017-01-07  2011-03-07  View
57171  CVE-2007-5088  Cross-site scripting (XSS) vulnerability in search/cust_bill_event.cgi in Freeside 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the failed parameter.    4.3  Medium  2017-01-07  2008-11-15  View
57939  CVE-2007-5914  Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated administrators to inject arbitrary PHP code via the DEBUG parameter, which can be executed by accessing config.inc.php. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2007-5913.    6.8  Medium  2017-01-07  2008-11-15  View
58195  CVE-2007-6192  The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-plaintext attack.    4.3  Medium  2017-01-07  2008-09-05  View

Page 3009 of 17672, showing 5 records out of 88360 total, starting on record 15041, ending on 15045

Actions