NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4811  CVE-2008-5024  Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.    7.5  High  2017-01-03  2012-10-30  View
4812  CVE-2008-5025  Stack-based buffer overflow in the hfs_cat_find_brec function in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfs filesystem image with an invalid catalog namelength field, a related issue to CVE-2008-4933.    7.8  High  2017-01-03  2013-08-28  View
4813  CVE-2008-5026  Microsoft SharePoint uses URLs with the same hostname and port number for a web site"s primary files and individual users" uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.    3.5  Low  2017-01-03  2010-03-01  View
4814  CVE-2008-5027  The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization checks, and trigger execution of arbitrary programs by this process, via an (a) custom form or a (b) browser addon.    6.5  Medium  2017-01-03  2016-12-07  View
4815  CVE-2008-5028  Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.    6.8  Medium  2017-01-03  2016-12-07  View

Page 963 of 17672, showing 5 records out of 88360 total, starting on record 4811, ending on 4815

Actions