NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48862  CVE-2009-1593  Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element.    4.3  Medium  2017-01-07  2009-05-23  View
48863  CVE-2009-1594  Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.    7.5  High  2017-01-07  2010-08-30  View
49014  CVE-2009-1745  Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access.    10  High  2017-01-07  2009-06-09  View
10022  CVE-2011-3367  Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.    Medium  2017-01-07  2011-11-30  View
44374  CVE-2012-2653  arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.    10  High  2017-01-19  2016-11-28  View

Page 1399 of 17672, showing 5 records out of 88360 total, starting on record 6991, ending on 6995

Actions