NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
8435 | CVE-2011-1504 | Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title. | 2 | 3.5 | Low | 2017-01-07 | 2011-05-31 | View | |
8434 | CVE-2011-1503 | The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL. | 2 | 3.5 | Low | 2017-01-07 | 2011-05-31 | View | |
8433 | CVE-2011-1502 | Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue. | 2 | 4 | Medium | 2017-01-07 | 2011-05-31 | View | |
8432 | CVE-2011-1501 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-1571. Reason: This candidate is a duplicate of CVE-2011-1571. Notes: All CVE users should reference CVE-2011-1571 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | 1 | 2017-01-07 | 2011-05-06 | View | |||
8431 | CVE-2011-1500 | PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user"s home directory, which allows local users to obtain Pandora credentials by reading this file. | 2 | 2.1 | Low | 2017-01-07 | 2011-04-19 | View |
Page 15986 of 17672, showing 5 records out of 88360 total, starting on record 79926, ending on 79930