NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65173 | CVE-2006-6629 | lib/WeBWorK/PG/Translator.pm in WeBWorK Program Generation (PG) Language before 2.3.1 uses an insufficiently restrictive regular expression to determine valid macro filenames, which allows attackers to load arbitrary macro files whose names contain the strings (1) dangerousMacros.pl, (2) PG.pl, or (3) IO.pl. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65429 | CVE-2006-6886 | phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.additions.inc.php in include/inc_lib/, which reveals the path in various error messages. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
65686 | CVE-2006-7143 | Cross-site scripting (XSS) vulnerability in Call Center Software 0.93 and earlier allows remote attackers to inject arbitrary web script or HTML via the problem description field. | 2 | 5.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
70550 | CVE-2004-0082 | The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
71830 | CVE-2004-1451 | Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View |
Page 873 of 17672, showing 5 records out of 88360 total, starting on record 4361, ending on 4365