NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 37891 | CVE-2013-1729 | The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element. | 2 | 2.6 | Low | 2017-01-18 | 2013-10-02 | View | |
| 59907 | CVE-2006-1193 | Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing." | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
| 62723 | CVE-2006-4066 | The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file, (2) .png file that crashes MSN Messenger, and (3) .jpg file that crashes Internet Explorer. NOTE: another researcher has not been able to reproduce this issue. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
| 77572 | CVE-2001-0092 | A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability. | 2 | 2.6 | Low | 2017-01-05 | 2008-09-10 | View | |
| 47620 | CVE-2009-0286 | Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter. | 2 | 2.6 | Low | 2017-01-07 | 2009-02-05 | View |
Page 15236 of 17672, showing 5 records out of 88360 total, starting on record 76176, ending on 76180