NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 15235 | CVE-2010-3900 | Midori before 0.2.5, when WebKitGTK+ before 1.1.14 or LibSoup before 2.29.91 is used, does not verify X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted server certificate, a related issue to CVE-2010-3312. | 2 | 5.8 | Medium | 2017-01-18 | 2011-02-17 | View | |
| 15234 | CVE-2010-3899 | IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents. | 2 | 5 | Medium | 2017-01-18 | 2010-12-01 | View | |
| 15233 | CVE-2010-3898 | IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site. | 2 | 5 | Medium | 2017-01-18 | 2010-12-01 | View | |
| 15232 | CVE-2010-3897 | ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file. | 2 | 5 | Medium | 2017-01-18 | 2010-12-01 | View | |
| 15231 | CVE-2010-3896 | The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do. | 2 | 7.5 | High | 2017-01-18 | 2010-12-01 | View |
Page 14626 of 17672, showing 5 records out of 88360 total, starting on record 73126, ending on 73130