NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
10275  CVE-2011-3703  AneCMS 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/menu/index.php and certain other files.    Medium  2017-01-07  2012-03-13  View
10787  CVE-2011-4319  Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.    4.3  Medium  2017-01-07  2012-08-24  View
11043  CVE-2011-4690  Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.    Medium  2017-01-07  2012-03-06  View
76835  CVE-2000-0594  BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.    Medium  2017-01-05  2008-09-10  View
11555  CVE-2011-5303  Cross-site scripting (XSS) vulnerability in Spitfire CMS 1.0.436 allows remote attackers to inject arbitrary web script or HTML via a cms_username cookie.    4.3  Medium  2017-01-07  2015-01-02  View

Page 1279 of 17672, showing 5 records out of 88360 total, starting on record 6391, ending on 6395

Actions