NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66231 | CVE-2005-0474 | SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie. | 2 | 6.4 | Medium | 2017-07-18 | 2017-07-10 | View | |
68279 | CVE-2005-2590 | Cross-site scripting (XSS) vulnerability in Parlano MindAlign 5.0 and later versions allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
68791 | CVE-2005-3129 | Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php. | 2 | 5.1 | Medium | 2017-07-18 | 2017-07-10 | View | |
70583 | CVE-2004-0119 | The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
70839 | CVE-2004-0391 | Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View |
Page 985 of 17672, showing 5 records out of 88360 total, starting on record 4921, ending on 4925