NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1866 | CVE-2008-1930 | The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
1867 | CVE-2008-1931 | Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allow local users to create, write, and read registry keys via a crafted IOCTL request. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
1868 | CVE-2008-1932 | Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arbitrary code via a crafted IOCTL request. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
1869 | CVE-2008-1933 | Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
1870 | CVE-2008-1934 | SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View |
Page 374 of 17672, showing 5 records out of 88360 total, starting on record 1866, ending on 1870