NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54551 | CVE-2007-2384 | The Script.aculo.us framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking." | 2 | 7.8 | High | 2017-01-07 | 2008-11-13 | View | |
| 73896 | CVE-2003-0791 | The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed. | 2 | 7.5 | High | 2017-01-03 | 2008-09-10 | View | |
| 45684 | CVE-2012-4245 | The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 59560 | CVE-2006-0830 | The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location" variable within the loop. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 19200 | CVE-2016-3385 | The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." | 2 | 9.3 | High | 2017-01-19 | 2016-12-23 | View |
Page 14442 of 17672, showing 5 records out of 88360 total, starting on record 72206, ending on 72210