NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80388 | CVE-2002-1435 | class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the "allow_url_fopen" setting is enabled via a URL in the config_atkroot parameter that points to the code. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
80644 | CVE-2002-1691 | Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
15620 | CVE-2010-4365 | SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php. | 2 | 7.5 | High | 2017-01-18 | 2010-12-02 | View | |
16132 | CVE-2010-4897 | SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action. | 2 | 7.5 | High | 2017-01-18 | 2011-10-10 | View | |
81924 | CVE-2016-8980 | IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. | 2 | 7.5 | High | 2017-02-15 | 2017-02-13 | View |
Page 464 of 17672, showing 5 records out of 88360 total, starting on record 2316, ending on 2320