NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4861 | CVE-2008-5074 | SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the linkid parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
4862 | CVE-2008-5075 | Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f) zipit.php, and (2) the view parameter to (g) browser.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-19 | View | |
4863 | CVE-2008-5076 | htop 0.7 writes process names to a terminal without sanitizing non-printable characters, which might allow local users to hide processes, modify arbitrary files, or have unspecified other impact via a process name with "crazy control strings." | 2 | 4.6 | Medium | 2017-01-03 | 2012-10-30 | View | |
4864 | CVE-2008-5077 | OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys. | 2 | 5.8 | Medium | 2017-01-03 | 2016-08-22 | View | |
4865 | CVE-2008-5078 | Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename. | 2 | 6.8 | Medium | 2017-01-03 | 2010-08-21 | View |
Page 973 of 17672, showing 5 records out of 88360 total, starting on record 4861, ending on 4865