NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11478 | CVE-2011-5218 | SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | 2 | 7.5 | High | 2017-01-07 | 2012-10-26 | View | |
| 77014 | CVE-2000-0773 | Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 11734 | CVE-2010-0159 | The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors. | 2 | 10 | High | 2017-01-18 | 2010-08-21 | View | |
| 77270 | CVE-2000-1036 | Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 11990 | CVE-2010-0434 | The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request. | 2 | 4.3 | Medium | 2017-01-18 | 2016-08-22 | View |
Page 14831 of 17672, showing 5 records out of 88360 total, starting on record 74151, ending on 74155