NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70723  CVE-2004-0272  SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.    7.5  High  2017-07-18  2017-07-10  View
71235  CVE-2004-0811  Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.    7.5  High  2017-07-18  2017-07-10  View
71491  CVE-2004-1099  Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.    10  High  2017-07-18  2017-07-10  View
71747  CVE-2004-1368  ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.    7.8  High  2017-07-18  2017-07-10  View
72003  CVE-2004-1624  Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).    7.2  High  2017-07-18  2017-07-10  View

Page 517 of 17672, showing 5 records out of 88360 total, starting on record 2581, ending on 2585

Actions