NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52486  CVE-2007-0258  Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo 2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: some of these details are obtained from third party information.    6.8  Medium  2017-01-07  2011-03-07  View
52742  CVE-2007-0518  Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.    7.5  High  2017-01-07  2008-11-13  View
52998  CVE-2007-0778  The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.    5.4  Medium  2017-01-07  2011-03-07  View
53254  CVE-2007-1046  Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt.    Medium  2017-01-07  2013-07-21  View
53510  CVE-2007-1320  Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.    7.2  High  2017-01-07  2012-11-05  View

Page 466 of 17672, showing 5 records out of 88360 total, starting on record 2326, ending on 2330

Actions