NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
13744  CVE-2010-2266  nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.    Medium  2017-01-18  2010-06-15  View
79280  CVE-2002-0270  Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.    4.3  Medium  2017-01-05  2016-10-17  View
79536  CVE-2002-0531  Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter.    Medium  2017-01-05  2008-09-05  View
79792  CVE-2002-0793  Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.    4.6  Medium  2017-07-18  2017-07-10  View
14512  CVE-2010-3092  The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.    5.5  Medium  2017-01-18  2010-09-22  View

Page 14845 of 17672, showing 5 records out of 88360 total, starting on record 74221, ending on 74225

Actions