NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
14860 | CVE-2010-3481 | Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from third party information. NOTE: the password vector might not be vulnerable. | 2 | 6.8 | Medium | 2017-01-18 | 2010-09-23 | View | |
80396 | CVE-2002-1443 | The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user"s input into the toolbar via an "onkeydown" event handler. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
15116 | CVE-2010-3771 | Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI. | 2 | 6.8 | Medium | 2017-01-18 | 2011-07-18 | View | |
80652 | CVE-2002-1700 | Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
15372 | CVE-2010-4054 | The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043. | 2 | 4.3 | Medium | 2017-01-18 | 2015-01-09 | View |
Page 1190 of 17672, showing 5 records out of 88360 total, starting on record 5946, ending on 5950