NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55569 | CVE-2007-3417 | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow remote attackers to inject arbitrary web script or HTML via a search string, which is not sanitized when an HREF attribute is printed by the (1) process_search or (2) show_recent_searches function. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
56081 | CVE-2007-3945 | Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes. | 2 | 6.4 | Medium | 2017-01-07 | 2011-03-07 | View | |
56337 | CVE-2007-4206 | Kaspersky Anti-Spam 3.0 MP1 before Critical Fix 2 (3.0.278.4) sets incorrect permissions for application files in certain upgrade scenarios, which might allow local users to gain privileges. | 2 | 4.4 | Medium | 2017-01-07 | 2008-11-15 | View | |
56849 | CVE-2007-4732 | Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function. | 2 | 4.9 | Medium | 2017-01-07 | 2011-03-07 | View | |
57105 | CVE-2007-5017 | Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 646 of 17672, showing 5 records out of 88360 total, starting on record 3226, ending on 3230