NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72276  CVE-2004-1898  Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.    10  High  2017-07-18  2017-07-10  View
72532  CVE-2004-2155  Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.    7.5  High  2017-07-18  2017-07-10  View
72788  CVE-2004-2411  The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks that do not use <script> tags, as demonstrated via javascript in IMG tags to (1) the cat parameter in shopdisplayproducts.asp or (2) the msg parameter in shoperror.asp, and possibly other vectors.    4.3  Medium  2017-07-18  2017-07-10  View
73300  CVE-2003-0153  bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.    Medium  2017-07-18  2017-07-10  View
73812  CVE-2003-0703  KisMAC before 0.05d trusts user-supplied variables to load arbitrary kernels or kernel modules, which allows local users to gain privileges via the $DRIVER_KEXT environment variable as used in (1) viha_driver.sh, (2) macjack_load.sh, or (3) airojack_load.sh, or (4) via similar techniques using exchangeKernel.sh.    7.2  High  2017-07-18  2017-07-10  View

Page 469 of 17672, showing 5 records out of 88360 total, starting on record 2341, ending on 2345

Actions