NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70926  CVE-2004-0490  cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.    7.2  High  2017-07-18  2017-07-10  View
5646  CVE-2008-5915  An unspecified function in the JavaScript implementation in Google Chrome creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.    2.1  Low  2017-01-03  2009-01-23  View
71182  CVE-2004-0755  The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.    2.1  Low  2017-07-18  2017-07-10  View
5902  CVE-2008-6171  includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.    9.3  High  2017-01-03  2009-05-14  View
71438  CVE-2004-1038  A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sensitive memory using a modified FireWire/IEEE 1394 client, thus bypassing intended restrictions that would normally require greater degrees of physical access to exploit. NOTE: this was reported in 2008 to affect Windows Vista, but some Linux-based operating systems have protection mechanisms against this attack.    7.2  High  2017-07-18  2017-07-10  View

Page 960 of 17672, showing 5 records out of 88360 total, starting on record 4796, ending on 4800

Actions