NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
41360  CVE-2013-6241  The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote authenticated users to obtain sensitive birthday, displayname, firstname, and surname information via a birthdays action to api/contacts, aka bug 29315.    Medium  2017-01-18  2014-12-29  View
65168  CVE-2006-6624  The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" sequences in the SIZE command.    Medium  2016-12-20  2011-03-07  View
3985  CVE-2008-4129  Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.    Medium  2017-01-03  2009-08-19  View
13713  CVE-2010-2230  The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.    Medium  2017-01-18  2010-09-09  View
17041  CVE-2016-0647  Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS.    Medium  2017-01-19  2016-12-02  View

Page 3141 of 17672, showing 5 records out of 88360 total, starting on record 15701, ending on 15705

Actions