NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71693 | CVE-2004-1313 | The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before invoking help, which allows local users to gain privileges. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
6413 | CVE-2008-6682 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-28 | View | |
71949 | CVE-2004-1570 | SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
6669 | CVE-2008-6938 | Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapiusers.txt. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-18 | View | |
72205 | CVE-2004-1827 | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 893 of 17672, showing 5 records out of 88360 total, starting on record 4461, ending on 4465