NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
13564  CVE-2010-2076  Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.    7.5  High  2017-01-18  2010-08-25  View
13820  CVE-2010-2342  SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.    7.5  High  2017-01-18  2010-06-21  View
79356  CVE-2002-0346  Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.    7.5  High  2017-01-05  2016-10-17  View
79612  CVE-2002-0607  members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL.    7.5  High  2017-01-05  2008-09-05  View
79868  CVE-2002-0870  The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.    7.5  High  2017-01-05  2008-09-05  View

Page 15696 of 17672, showing 5 records out of 88360 total, starting on record 78476, ending on 78480

Actions