NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 15495 | CVE-2010-4212 | The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data. | 2 | 1.9 | Low | 2017-01-18 | 2010-12-22 | View | |
| 15494 | CVE-2010-4211 | The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate. | 2 | 2.9 | Low | 2017-01-18 | 2010-11-09 | View | |
| 15493 | CVE-2010-4210 | The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possibly execute arbitrary code via vectors related to opening a file on a file system that uses pseudofs. | 2 | 7.2 | High | 2017-01-18 | 2010-11-22 | View | |
| 15492 | CVE-2010-4209 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf. | 2 | 4.3 | Medium | 2017-01-18 | 2011-02-05 | View | |
| 15491 | CVE-2010-4208 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf. | 2 | 4.3 | Medium | 2017-01-18 | 2011-02-05 | View |
Page 14574 of 17672, showing 5 records out of 88360 total, starting on record 72866, ending on 72870