NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11175 | CVE-2011-4837 | Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs. | 2 | 6.8 | Medium | 2017-01-07 | 2011-12-15 | View | |
| 11174 | CVE-2011-4836 | Cross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web script or HTML via a request for a crafted URI. | 2 | 4.3 | Medium | 2017-01-07 | 2011-12-15 | View | |
| 11173 | CVE-2011-4835 | Directory traversal vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to access arbitrary files via unspecified vectors. | 2 | 7.5 | High | 2017-01-07 | 2011-12-15 | View | |
| 11172 | CVE-2011-4834 | The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt. | 2 | 4.6 | Medium | 2017-01-07 | 2011-12-15 | View | |
| 11171 | CVE-2011-4833 | Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2012-02-09 | View |
Page 15438 of 17672, showing 5 records out of 88360 total, starting on record 77186, ending on 77190