NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
9885 | CVE-2011-3201 | GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email. | 2 | 4.3 | Medium | 2017-01-07 | 2016-11-22 | View | |
9884 | CVE-2011-3200 | Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers to cause a denial of service (application exit) via a long TAG in a legacy syslog message. | 2 | 5 | Medium | 2017-01-07 | 2011-09-22 | View | |
9883 | CVE-2011-3199 | Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0.34.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message body of a support ticket or unspecified vectors to the (2) DNS and (3) MX form, as demonstrated by the "Domain root TXT record:" field. | 2 | 3.5 | Low | 2017-01-07 | 2014-03-27 | View | |
9882 | CVE-2011-3198 | Domain Technologie Control (DTC) before 0.34.1 includes a password in the -b command line argument to htpasswd, which might allow local users to read the password by listing the process and its arguments. | 2 | 2.1 | Low | 2017-01-07 | 2014-03-21 | View | |
9881 | CVE-2011-3197 | SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the addrlink parameter to shared/inc/forms/domain_info.php. NOTE: CVE-2011-3197 has been SPLIT due to findings by different researchers. CVE-2011-5272 has been assigned for the vps_note parameter to dtcadmin/logPushlet.php vector. | 2 | 6.5 | Medium | 2017-01-07 | 2014-03-27 | View |
Page 15696 of 17672, showing 5 records out of 88360 total, starting on record 78476, ending on 78480