NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
13347 | CVE-2010-1854 | Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to inject arbitrary web script or HTML via the id_auk parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might be resultant from CVE-2010-1855. | 2 | 4.3 | Medium | 2017-01-18 | 2010-05-10 | View | |
13603 | CVE-2010-2116 | The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do. | 2 | 6.5 | Medium | 2017-01-18 | 2010-06-01 | View | |
14371 | CVE-2010-2940 | The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are enabled, allows remote attackers to bypass the authentication requirements of pam_authenticate via an empty password. | 2 | 5.1 | Medium | 2017-01-18 | 2010-08-31 | View | |
14883 | CVE-2010-3504 | Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2010-11-11 | View | |
15139 | CVE-2010-3795 | QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file. | 2 | 6.8 | Medium | 2017-01-18 | 2010-12-11 | View |
Page 1281 of 17672, showing 5 records out of 88360 total, starting on record 6401, ending on 6405