NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71235 | CVE-2004-0811 | Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71491 | CVE-2004-1099 | Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
71747 | CVE-2004-1368 | ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script. | 2 | 7.8 | High | 2017-07-18 | 2017-07-10 | View | |
72003 | CVE-2004-1624 | Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe). | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
72259 | CVE-2004-1881 | SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 773 of 17672, showing 5 records out of 88360 total, starting on record 3861, ending on 3865