NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
63821  CVE-2006-5215  The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user"s Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.    2.6  Low  2016-12-20  2008-09-05  View
8434  CVE-2011-1503  The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.    3.5  Low  2017-01-07  2011-05-31  View
44521  CVE-2012-2825  The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.    Medium  2017-01-19  2014-01-27  View
48968  CVE-2009-1699  The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."    7.1  High  2017-01-07  2012-03-30  View
21062  CVE-2016-6185  The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.    4.6  Medium  2017-01-19  2016-11-28  View

Page 15094 of 17672, showing 5 records out of 88360 total, starting on record 75466, ending on 75470

Actions