NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
64665  CVE-2006-6104  The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.    Medium  2016-12-20  2011-03-07  View
29946  CVE-2014-1265  The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local users to bypass intended access restrictions by changing the current time on the system clock.    4.6  Medium  2017-01-19  2014-02-27  View
72389  CVE-2004-2012  The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.    7.2  High  2017-07-18  2017-07-10  View
13354  CVE-2010-1861  The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an object"s __sleep function to interrupt an internal call to the shm_put_var function, which triggers access of a freed resource.    6.4  Medium  2017-01-18  2010-05-10  View
60230  CVE-2006-1522  The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.    4.9  Medium  2016-12-20  2012-03-19  View

Page 14706 of 17672, showing 5 records out of 88360 total, starting on record 73526, ending on 73530

Actions