NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
81109  CVE-2002-2158  zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message.    Medium  2017-01-05  2008-09-05  View
15829  CVE-2010-4580  Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive information via an input field that has the same name as an input field on a previously visited web site.    Medium  2017-01-18  2011-01-22  View
81365  CVE-2002-2414  Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash).    4.3  Medium  2017-01-05  2016-10-17  View
16085  CVE-2010-4850  Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web script or HTML via the (1) post_content parameter to post/edit/2/p1.html, related to views/post.php; the (2) slogan parameter to admin/site/2.html, related to views/admin.php; or the (3) subcatname or (4) description parameter to admin/forum/create_sub.html, related to views/admin.php.    4.3  Medium  2017-01-18  2012-02-13  View
16341  CVE-2010-5106  The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.    6.5  Medium  2017-01-18  2012-09-17  View

Page 15085 of 17672, showing 5 records out of 88360 total, starting on record 75421, ending on 75425

Actions