NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70723 | CVE-2004-0272 | SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71235 | CVE-2004-0811 | Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71491 | CVE-2004-1099 | Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
71747 | CVE-2004-1368 | ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script. | 2 | 7.8 | High | 2017-07-18 | 2017-07-10 | View | |
72003 | CVE-2004-1624 | Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe). | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View |
Page 517 of 17672, showing 5 records out of 88360 total, starting on record 2581, ending on 2585