NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
521 | CVE-2008-0546 | Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp. | 2 | 7.5 | High | 2017-01-03 | 2009-08-20 | View | |
66057 | CVE-2005-0294 | minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
777 | CVE-2008-0806 | wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file. | 2 | 3.6 | Low | 2017-01-03 | 2008-09-05 | View | |
66313 | CVE-2005-0560 | Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
1033 | CVE-2008-1072 | The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug. | 2 | 4.7 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 613 of 17672, showing 5 records out of 88360 total, starting on record 3061, ending on 3065