NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
1976  CVE-2008-2041  Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root.    10  High  2017-01-03  2008-11-15  View
1977  CVE-2008-2042  The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.    9.3  High  2017-01-03  2011-03-07  View
1978  CVE-2008-2043  Multiple cross-site request forgery (CSRF) vulnerabilities in cPanel, possibly 11.18.3 and 11.19.3, allow remote attackers to (1) execute arbitrary code via the command1 parameter to frontend/x2/cron/editcronsimple.html, and perform various administrative actions via (2) frontend/x2/sql/adddb.html, (3) frontend/x2/sql/adduser.html, and (4) frontend/x2/ftp/doaddftp.html.    4.3  Medium  2017-01-03  2011-03-07  View
1979  CVE-2008-2044  includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the "true" string literal instead of the true boolean literal, which allows remote attackers to bypass authentication and execute arbitrary code by setting this variable to 1, as demonstrated by uploading a PHP script via an add action to projects_site/uploadfile.php.    7.5  High  2017-01-03  2009-08-19  View
1980  CVE-2008-2045  Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.    Medium  2017-01-03  2011-03-07  View

Page 396 of 17672, showing 5 records out of 88360 total, starting on record 1976, ending on 1980

Actions