NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
17 | CVE-2008-0017 | The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow. | 2 | 9.3 | High | 2017-01-03 | 2012-10-30 | View | |
65553 | CVE-2006-7010 | The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable"s data type to integer when the variable"s default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
273 | CVE-2008-0288 | Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
65809 | CVE-2005-0015 | diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
66065 | CVE-2005-0302 | SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 806 of 17672, showing 5 records out of 88360 total, starting on record 4026, ending on 4030