NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
10275 | CVE-2011-3703 | AneCMS 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/menu/index.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-03-13 | View | |
10787 | CVE-2011-4319 | Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring. | 2 | 4.3 | Medium | 2017-01-07 | 2012-08-24 | View | |
11043 | CVE-2011-4690 | Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code. | 2 | 5 | Medium | 2017-01-07 | 2012-03-06 | View | |
76835 | CVE-2000-0594 | BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
11555 | CVE-2011-5303 | Cross-site scripting (XSS) vulnerability in Spitfire CMS 1.0.436 allows remote attackers to inject arbitrary web script or HTML via a cms_username cookie. | 2 | 4.3 | Medium | 2017-01-07 | 2015-01-02 | View |
Page 1279 of 17672, showing 5 records out of 88360 total, starting on record 6391, ending on 6395