NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80149 | CVE-2002-1157 | Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
14869 | CVE-2010-3490 | Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root. | 2 | 6.5 | Medium | 2017-01-18 | 2013-09-03 | View | |
80405 | CVE-2002-1452 | Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View | |
15125 | CVE-2010-3780 | Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions. | 2 | 4 | Medium | 2017-01-18 | 2011-08-26 | View | |
80661 | CVE-2002-1710 | The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file. | 2 | 3.6 | Low | 2017-07-18 | 2017-07-10 | View |
Page 1449 of 17672, showing 5 records out of 88360 total, starting on record 7241, ending on 7245