NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
8455  CVE-2011-1525  Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted frame in an Internet Video Recording (IVR) file.    9.3  High  2017-01-07  2011-10-17  View
8454  CVE-2011-1524  Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web script or HTML via the username field, as demonstrated by injecting an IFRAME element into the event log, a different vulnerability than CVE-2011-0545.    4.3  Medium  2017-01-07  2013-02-06  View
8453  CVE-2011-1523  Cross-site scripting (XSS) vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter.    4.3  Medium  2017-01-07  2011-09-21  View
8452  CVE-2011-1522  Multiple SQL injection vulnerabilities in the DoctrineDBALPlatformsAbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field.    7.5  High  2017-01-07  2011-05-31  View
8451  CVE-2011-1521  The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.    6.4  Medium  2017-01-07  2014-02-20  View

Page 15982 of 17672, showing 5 records out of 88360 total, starting on record 79906, ending on 79910

Actions