NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
7741 | CVE-2011-0700 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box. | 2 | 3.5 | Low | 2017-01-07 | 2011-04-20 | View | |
7742 | CVE-2011-0701 | wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter. | 2 | 4 | Medium | 2017-01-07 | 2011-04-20 | View | |
7743 | CVE-2011-0702 | The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to overwrite arbitrary files via a symlink attack on a /tmp/feh_ temporary file. | 2 | 3.3 | Low | 2017-01-07 | 2011-02-15 | View | |
7744 | CVE-2011-0706 | The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor." | 2 | 7.5 | High | 2017-01-07 | 2014-10-04 | View | |
7745 | CVE-2011-0707 | Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message. | 2 | 4.3 | Medium | 2017-01-07 | 2014-02-20 | View |
Page 1549 of 17672, showing 5 records out of 88360 total, starting on record 7741, ending on 7745