NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
71693  CVE-2004-1313  The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before invoking help, which allows local users to gain privileges.    7.2  High  2017-07-18  2017-07-10  View
6413  CVE-2008-6682  Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.    4.3  Medium  2017-01-03  2009-04-28  View
71949  CVE-2004-1570  SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.    7.5  High  2017-07-18  2017-07-10  View
6669  CVE-2008-6938  Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapiusers.txt.    4.3  Medium  2017-01-03  2009-08-18  View
72205  CVE-2004-1827  Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.    4.3  Medium  2017-07-18  2017-07-10  View

Page 893 of 17672, showing 5 records out of 88360 total, starting on record 4461, ending on 4465

Actions