NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52742 | CVE-2007-0518 | Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt. | 2 | 7.5 | High | 2017-01-07 | 2008-11-13 | View | |
52998 | CVE-2007-0778 | The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache. | 2 | 5.4 | Medium | 2017-01-07 | 2011-03-07 | View | |
53254 | CVE-2007-1046 | Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt. | 2 | 5 | Medium | 2017-01-07 | 2013-07-21 | View | |
53510 | CVE-2007-1320 | Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow. | 2 | 7.2 | High | 2017-01-07 | 2012-11-05 | View | |
53766 | CVE-2007-1582 | The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 411 of 17672, showing 5 records out of 88360 total, starting on record 2051, ending on 2055