NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39356 | CVE-2013-3586 | Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie. | 2 | 7.6 | High | 2017-01-18 | 2013-08-29 | View | |
54460 | CVE-2007-2293 | Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE. | 2 | 7.6 | High | 2017-01-07 | 2011-03-07 | View | |
73405 | CVE-2003-0270 | The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections. | 2 | 7.6 | High | 2017-07-18 | 2017-07-10 | View | |
9917 | CVE-2011-3235 | WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1. | 2 | 7.6 | High | 2017-01-07 | 2013-11-02 | View | |
13757 | CVE-2010-2279 | The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors. | 2 | 7.6 | High | 2017-01-18 | 2010-06-16 | View |
Page 15845 of 17672, showing 5 records out of 88360 total, starting on record 79221, ending on 79225