NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72587 | CVE-2004-2210 | Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to login.asp, or (6) the email parameter to subscribe/default.asp. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
73099 | CVE-2004-2722 | ** DISPUTED ** Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue. | 2 | 2.1 | Low | 2016-12-20 | 2008-09-05 | View | |
58763 | CVE-2006-0019 | Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59019 | CVE-2006-0279 | Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component. | 2 | 10 | High | 2016-12-20 | 2012-10-22 | View | |
59275 | CVE-2006-0538 | CipherTrust IronMail 5.0.1, when "Denial of Service Protection" is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with malformed TCP packets from multiple connections. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View |
Page 807 of 17672, showing 5 records out of 88360 total, starting on record 4031, ending on 4035