NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
9615  CVE-2011-2894  Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.    6.8  Medium  2017-01-07  2012-02-13  View
9614  CVE-2011-2893  The DataPilot feature in IBM Lotus Symphony 3 before FP3 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .xls spreadsheet with an invalid Value reference.    4.3  Medium  2017-01-07  2011-08-11  View
9613  CVE-2011-2892  Joomla! 1.6.x before 1.6.2 does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.    4.3  Medium  2017-01-07  2011-07-29  View
9612  CVE-2011-2891  Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message, a different vulnerability than CVE-2011-2488.    Medium  2017-01-07  2011-08-10  View
9611  CVE-2011-2890  The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obtain sensitive information via vectors involving the base variable, leading to disclosure of the installation path, a different vulnerability than CVE-2011-2488.    Medium  2017-01-07  2011-08-10  View

Page 15750 of 17672, showing 5 records out of 88360 total, starting on record 78746, ending on 78750

Actions