NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71011 | CVE-2004-0584 | Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
71267 | CVE-2004-0844 | Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability." | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71523 | CVE-2004-1133 | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as "Connection" or (2) invalid parameters whose values are echoed in the resulting error message. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
71779 | CVE-2004-1400 | The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
72035 | CVE-2004-1656 | CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 625 of 17672, showing 5 records out of 88360 total, starting on record 3121, ending on 3125