NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16128  CVE-2010-4893  Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the category parameter in a details action.    4.3  Medium  2017-01-18  2012-05-14  View
81664  CVE-2017-5594  An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.    4.3  Medium  2017-02-07  2017-01-27  View
16384  CVE-2010-5175  ** DISPUTED ** Race condition in PrivateFirewall 7.0.20.37 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.    6.2  Medium  2017-01-18  2012-08-27  View
16896  CVE-2016-0480  Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0481, CVE-2016-0482, CVE-2016-0485, and CVE-2016-0486. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the TMAPReportImage parameter.    Medium  2017-01-19  2016-12-07  View
82432  CVE-2016-8693  Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the imginfo command.    6.8  Medium  2017-02-28  2017-02-22  View

Page 13 of 17672, showing 5 records out of 88360 total, starting on record 61, ending on 65

<<first 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 last>>

Actions