NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
69915 | CVE-2005-4317 | Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote attackers to use the _SERVER[REMOTE_ADDR] parameter to (1) conduct cross-site scripting (XSS) attacks in the stats module or (2) execute arbitrary code via an eval injection attack in the wrapper option in index2.php. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
4635 | CVE-2008-4821 | Adobe Flash Player 9.0.124.0 and earlier, when a Mozilla browser is used, does not properly interpret jar: URLs, which allows attackers to obtain sensitive information via unknown vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2012-10-30 | View | |
70427 | CVE-2005-4838 | Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
5147 | CVE-2008-5369 | noip2 in noip2 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/noip2 temporary file. | 2 | 6.9 | Medium | 2017-01-03 | 2008-12-09 | View | |
70683 | CVE-2004-0232 | Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 975 of 17672, showing 5 records out of 88360 total, starting on record 4871, ending on 4875