NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
10786 | CVE-2011-4318 | Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname. | 2 | 5.8 | Medium | 2017-01-07 | 2013-03-07 | View | |
11042 | CVE-2011-4689 | Microsoft Internet Explorer 6 through 9 does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code. | 2 | 5 | Medium | 2017-01-07 | 2012-03-06 | View | |
76834 | CVE-2000-0593 | WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
11554 | CVE-2011-5302 | Cross-site request forgery (CSRF) vulnerability in adm/admin_edit.php in PHPDug 2.0.0 allows remote attackers to hijack the authentication of administrators for requests that modify credentials. | 2 | 6.8 | Medium | 2017-01-07 | 2015-01-02 | View | |
77346 | CVE-2000-1114 | Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20". | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 1239 of 17672, showing 5 records out of 88360 total, starting on record 6191, ending on 6195