NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
12277  CVE-2010-0731  The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.    7.5  High  2017-01-18  2010-09-09  View
13045  CVE-2010-1521  SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php.    7.5  High  2017-01-18  2012-11-05  View
78837  CVE-2001-1403  Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser"s location bar.    7.5  High  2017-01-05  2016-10-17  View
79093  CVE-2002-0077  Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.    7.5  High  2017-01-05  2016-10-17  View
13813  CVE-2010-2335  SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to execute arbitrary SQL commands via the news parameter.    7.5  High  2017-01-18  2010-06-24  View

Page 15606 of 17672, showing 5 records out of 88360 total, starting on record 78026, ending on 78030

Actions