NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 36117 | CVE-2014-9414 | The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php. | 2 | 6.8 | Medium | 2017-01-19 | 2015-01-12 | View | |
| 75403 | CVE-1999-0753 | The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. | 2 | 7.5 | High | 2017-01-05 | 2008-09-09 | View | |
| 76322 | CVE-2000-0079 | The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
| 82589 | CVE-2017-5928 | The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now Time to Tick approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 protection mechanism in place, which makes it easier for remote attackers to conduct AnC attacks via crafted JavaScript code. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-24 | View | |
| 8072 | CVE-2011-1096 | The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, allows remote attackers to obtain plaintext data via a chosen-ciphertext attack on SOAP responses, aka "character encoding pattern attack." | 2 | 5 | Medium | 2017-01-07 | 2013-10-30 | View |
Page 14904 of 17672, showing 5 records out of 88360 total, starting on record 74516, ending on 74520