NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
69397 | CVE-2005-3759 | Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments. | 2 | 5.8 | Medium | 2017-01-03 | 2011-09-13 | View | |
69653 | CVE-2005-4015 | PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attackers to fill the log files via a large number of requests, as demonstrated using pixel.php. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
69909 | CVE-2005-4311 | Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
70165 | CVE-2005-4576 | Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-20 | View | |
5141 | CVE-2008-5363 | The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-20 | View |
Page 758 of 17672, showing 5 records out of 88360 total, starting on record 3786, ending on 3790