NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
80330  CVE-2002-1377  vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.    4.6  Medium  2017-01-05  2016-10-17  View
15050  CVE-2010-3693  Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via vectors related to displaying mailbox names.    4.3  Medium  2017-01-18  2011-05-26  View
15306  CVE-2010-3978  Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/products.json, (2) admin/users.json, or (3) admin/overview/get_report_data, related to a "JSON hijacking" issue.    Medium  2017-01-18  2013-09-03  View
80842  CVE-2002-1891  Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request.    7.5  High  2017-01-05  2008-09-05  View
15562  CVE-2010-4299  Heap-based buffer overflow in ZfHIPCND.exe in Novell Zenworks 7 Handheld Management (ZHM) allows remote attackers to execute arbitrary code via a crafted request to TCP port 2400.    9.3  High  2017-01-30  2017-01-26  View

Page 14423 of 17672, showing 5 records out of 88360 total, starting on record 72111, ending on 72115

Actions