NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
9260 | CVE-2011-2481 | Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression. | 2 | 4.6 | Medium | 2017-05-27 | 2017-05-22 | View | |
75308 | CVE-1999-0656 | The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
10028 | CVE-2011-3376 | org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality. | 2 | 4.4 | Medium | 2017-05-27 | 2017-05-22 | View | |
10284 | CVE-2011-3712 | CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-03-13 | View | |
75820 | CVE-1999-1170 | IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920. | 2 | 4.6 | Medium | 2017-01-05 | 2016-10-17 | View |
Page 1593 of 17672, showing 5 records out of 88360 total, starting on record 7961, ending on 7965