NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54551  CVE-2007-2384  The Script.aculo.us framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."    7.8  High  2017-01-07  2008-11-13  View
73896  CVE-2003-0791  The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.    7.5  High  2017-01-03  2008-09-10  View
45684  CVE-2012-4245  The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.    6.8  Medium  2017-01-19  2016-12-02  View
59560  CVE-2006-0830  The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location" variable within the loop.    7.5  High  2016-12-20  2008-09-05  View
19200  CVE-2016-3385  The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."    9.3  High  2017-01-19  2016-12-23  View

Page 14442 of 17672, showing 5 records out of 88360 total, starting on record 72206, ending on 72210

Actions