NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63744 | CVE-2006-5138 | Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
65024 | CVE-2006-6479 | Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4) membre.dwt.php, and (5) admin/admin_config/Aide.php. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
65280 | CVE-2006-6736 | Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue." | 2 | 4.3 | Medium | 2016-12-20 | 2011-04-27 | View | |
65537 | CVE-2006-6994 | Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitrary ASP files by removing the client-side security checks. | 2 | 6.4 | Medium | 2016-12-20 | 2016-11-18 | View | |
257 | CVE-2008-0272 | Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 36 of 17672, showing 5 records out of 88360 total, starting on record 176, ending on 180