NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 41360 | CVE-2013-6241 | The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote authenticated users to obtain sensitive birthday, displayname, firstname, and surname information via a birthdays action to api/contacts, aka bug 29315. | 2 | 4 | Medium | 2017-01-18 | 2014-12-29 | View | |
| 65168 | CVE-2006-6624 | The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" sequences in the SIZE command. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 3985 | CVE-2008-4129 | Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality. | 2 | 4 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 13713 | CVE-2010-2230 | The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input. | 2 | 4 | Medium | 2017-01-18 | 2010-09-09 | View | |
| 17041 | CVE-2016-0647 | Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS. | 2 | 4 | Medium | 2017-01-19 | 2016-12-02 | View |
Page 3141 of 17672, showing 5 records out of 88360 total, starting on record 15701, ending on 15705