NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 13294 | CVE-2010-1794 | The webdav_mount function in webdav_vfsops.c in the WebDAV kernel extension (aka webdav_fs.kext) for Mac OS X 10.6 allows local users to cause a denial of service (panic) via a mount request with a large integer in the pa_socket_namelen field. | 2 | 4.9 | Medium | 2017-01-18 | 2010-08-03 | View | |
| 27908 | CVE-2015-7223 | The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site. | 2 | 4 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 18802 | CVE-2016-2817 | The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-30 | View | |
| 35843 | CVE-2014-9022 | The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x before 7.x-1.8 for Drupal allows remote attackers to bypass the "disabled" restriction and modify read-only components via a crafted form. | 2 | 6.4 | Medium | 2017-01-19 | 2014-11-20 | View | |
| 51650 | CVE-2009-4533 | The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, does not prevent caching of a page that contains token placeholders for a default value, which allows remote attackers to read session variables via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2010-01-04 | View |
Page 14988 of 17672, showing 5 records out of 88360 total, starting on record 74936, ending on 74940