NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 15818 | CVE-2010-4568 | Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers to obtain access to arbitrary accounts via unspecified vectors, related to an insufficient number of calls to the srand function. | 2 | 7.5 | High | 2017-01-18 | 2011-10-25 | View | |
| 81354 | CVE-2002-2403 | Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 16074 | CVE-2010-4839 | SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action. | 2 | 7.5 | High | 2017-01-18 | 2011-09-14 | View | |
| 16330 | CVE-2010-5095 | Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x before 2.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination. | 2 | 4.3 | Medium | 2017-01-18 | 2012-08-27 | View | |
| 81866 | CVE-2016-6500 | Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning. | 2017-02-08 | 2017-02-03 | View |
Page 14424 of 17672, showing 5 records out of 88360 total, starting on record 72116, ending on 72120