NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48862 | CVE-2009-1593 | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-23 | View | |
48863 | CVE-2009-1594 | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL. | 2 | 7.5 | High | 2017-01-07 | 2010-08-30 | View | |
49014 | CVE-2009-1745 | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access. | 2 | 10 | High | 2017-01-07 | 2009-06-09 | View | |
10022 | CVE-2011-3367 | Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text. | 2 | 5 | Medium | 2017-01-07 | 2011-11-30 | View | |
44374 | CVE-2012-2653 | arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon. | 2 | 10 | High | 2017-01-19 | 2016-11-28 | View |
Page 1399 of 17672, showing 5 records out of 88360 total, starting on record 6991, ending on 6995