NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
9010  CVE-2011-2192  The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.    4.3  Medium  2017-01-07  2012-02-03  View
9009  CVE-2011-2191  Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrated by a crafted nickname field to vserver/apply.    6.8  Medium  2017-01-07  2011-11-23  View
9008  CVE-2011-2190  The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.    2.1  Low  2017-01-07  2012-05-14  View
9007  CVE-2011-2189  net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.    7.8  High  2017-01-07  2012-09-17  View
9006  CVE-2011-2188  LuaExpat before 1.2.0 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.    Medium  2017-01-07  2011-06-28  View

Page 15871 of 17672, showing 5 records out of 88360 total, starting on record 79351, ending on 79355

Actions