NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
7935 | CVE-2011-0911 | Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: it is possible that this overlaps CVE-2011-0535. | 2 | 4.3 | Medium | 2017-01-07 | 2011-02-14 | View | |
7934 | CVE-2011-0910 | The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks. | 2 | 6.4 | Medium | 2017-01-07 | 2011-02-14 | View | |
7933 | CVE-2011-0909 | Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | 2 | 4.3 | Medium | 2017-01-07 | 2011-02-14 | View | |
7932 | CVE-2011-0908 | Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | 2 | 5.8 | Medium | 2017-01-07 | 2011-05-05 | View | |
7931 | CVE-2011-0905 | The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation. | 2 | 3.5 | Low | 2017-01-07 | 2014-02-20 | View |
Page 16086 of 17672, showing 5 records out of 88360 total, starting on record 80426, ending on 80430