NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62363 | CVE-2006-3695 | Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-16 | View | |
62619 | CVE-2006-3961 | Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
62875 | CVE-2006-4234 | PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
63131 | CVE-2006-4496 | Cross-site scripting (XSS) vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
63387 | CVE-2006-4763 | IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client"s Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user"s privileges by intercepting the LtpaToken cookie. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 907 of 17672, showing 5 records out of 88360 total, starting on record 4531, ending on 4535