NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5895 | CVE-2008-6164 | Cross-site scripting (XSS) vulnerability in index.php in DreamCost HostAdmin 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
71431 | CVE-2004-1031 | fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as /proc/self/cmdline or /proc/self/environ. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
6151 | CVE-2008-6420 | Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php, and (3) webadmin/download_file.php. | 2 | 5 | Medium | 2017-01-03 | 2009-04-08 | View | |
71687 | CVE-2004-1307 | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow. | 2 | 7.5 | High | 2016-12-20 | 2010-08-21 | View | |
6407 | CVE-2008-6676 | QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-03 | 2009-04-25 | View |
Page 836 of 17672, showing 5 records out of 88360 total, starting on record 4176, ending on 4180