NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67598  CVE-2005-1880  everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.    2.1  Low  2017-01-03  2008-09-05  View
2318  CVE-2008-2402  The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents.    Medium  2017-01-03  2011-03-07  View
2574  CVE-2008-2676  SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.    7.5  High  2017-01-03  2008-09-05  View
2830  CVE-2008-2936  Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.    6.2  Medium  2017-01-03  2011-03-07  View
68366  CVE-2005-2677  ACNews stores the database in a file under the web document root with a db.inc extension and insufficient access control, which allows remote attackers to obtain sensitive information such as the full pathname of the server.    Medium  2017-01-03  2008-09-05  View

Page 841 of 17672, showing 5 records out of 88360 total, starting on record 4201, ending on 4205

Actions