NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57659 | CVE-2007-5594 | Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
59451 | CVE-2006-0720 | Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file. | 2 | 7.6 | High | 2016-12-20 | 2008-09-05 | View | |
63291 | CVE-2006-4658 | Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses sequential message numbers in generated URLs that are not filtered if the user replies to a message, which might allow remote attackers to determine mail usage patterns. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63547 | CVE-2006-4939 | backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63803 | CVE-2006-5197 | PDshopPro stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) /pdshoppro.mdb, (2) /data/pdshoppro.mdb, or (3) /shoppro/data/pdshoppro.mdb. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 380 of 17672, showing 5 records out of 88360 total, starting on record 1896, ending on 1900