NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
8653 | CVE-2011-1766 | includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation. | 2 | 5.8 | Medium | 2017-01-07 | 2011-06-15 | View | |
8909 | CVE-2011-2085 | Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users. | 2 | 6.8 | Medium | 2017-01-07 | 2012-09-28 | View | |
9421 | CVE-2011-2682 | The Login component in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote authenticated users to cause a denial of service (license consumption) by trying to login to DOORS Web Access with a new user account that has never been used for a DOORS login. | 2 | 4 | Medium | 2017-01-07 | 2011-09-06 | View | |
74957 | CVE-1999-0288 | The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets. | 2 | 5 | Medium | 2017-01-05 | 2008-09-09 | View | |
9677 | CVE-2011-2979 | Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search. NOTE: this vulnerability exists because of a CVE-2010-2756 regression. | 2 | 5 | Medium | 2017-01-07 | 2011-10-25 | View |
Page 15862 of 17672, showing 5 records out of 88360 total, starting on record 79306, ending on 79310