NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 13219 | CVE-2010-1715 | Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-18 | 2010-06-01 | View | |
| 79011 | CVE-2001-1580 | Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 13731 | CVE-2010-2253 | lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory. | 2 | 6.8 | Medium | 2017-01-18 | 2010-11-06 | View | |
| 13987 | CVE-2010-2529 | Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of service (hang) via a crafted echo response. | 2 | 5 | Medium | 2017-01-18 | 2010-07-28 | View | |
| 14243 | CVE-2010-2809 | The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document. | 2 | 6.8 | Medium | 2017-01-18 | 2010-08-25 | View |
Page 14394 of 17672, showing 5 records out of 88360 total, starting on record 71966, ending on 71970