NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81282 | CVE-2002-2331 | W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments. | 2 | 5.8 | Medium | 2017-01-05 | 2008-09-05 | View | |
52866 | CVE-2007-0644 | Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions. | 2 | 7.1 | High | 2017-01-07 | 2008-09-05 | View | |
53378 | CVE-2007-1171 | SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
53634 | CVE-2007-1450 | SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
56706 | CVE-2007-4586 | Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent attackers to execute arbitrary code, probably during Unicode conversion, as demonstrated by a long string in the first argument to the iis_getservicestate function, related to the ServiceId argument to the (1) fnStartService, (2) fnGetServiceState, (3) fnStopService, and possibly other functions. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View |
Page 869 of 17672, showing 5 records out of 88360 total, starting on record 4341, ending on 4345