NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71440 | CVE-2004-1043 | Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability." | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71696 | CVE-2004-1316 | Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '' (backslash) character, which prevents a string from being NULL terminated. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71952 | CVE-2004-1573 | The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
72208 | CVE-2004-1830 | error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
72464 | CVE-2004-2087 | Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 319 of 17672, showing 5 records out of 88360 total, starting on record 1591, ending on 1595