NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
14860  CVE-2010-3481  Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from third party information. NOTE: the password vector might not be vulnerable.    6.8  Medium  2017-01-18  2010-09-23  View
80396  CVE-2002-1443  The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user"s input into the toolbar via an "onkeydown" event handler.    Medium  2017-01-05  2008-09-05  View
15116  CVE-2010-3771  Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.    6.8  Medium  2017-01-18  2011-07-18  View
80652  CVE-2002-1700  Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.    4.3  Medium  2017-07-18  2017-07-10  View
15372  CVE-2010-4054  The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.    4.3  Medium  2017-01-18  2015-01-09  View

Page 1190 of 17672, showing 5 records out of 88360 total, starting on record 5946, ending on 5950

Actions