NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
8455 | CVE-2011-1525 | Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted frame in an Internet Video Recording (IVR) file. | 2 | 9.3 | High | 2017-01-07 | 2011-10-17 | View | |
8454 | CVE-2011-1524 | Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web script or HTML via the username field, as demonstrated by injecting an IFRAME element into the event log, a different vulnerability than CVE-2011-0545. | 2 | 4.3 | Medium | 2017-01-07 | 2013-02-06 | View | |
8453 | CVE-2011-1523 | Cross-site scripting (XSS) vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2011-09-21 | View | |
8452 | CVE-2011-1522 | Multiple SQL injection vulnerabilities in the DoctrineDBALPlatformsAbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field. | 2 | 7.5 | High | 2017-01-07 | 2011-05-31 | View | |
8451 | CVE-2011-1521 | The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs. | 2 | 6.4 | Medium | 2017-01-07 | 2014-02-20 | View |
Page 15982 of 17672, showing 5 records out of 88360 total, starting on record 79906, ending on 79910