NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
7745  CVE-2011-0707  Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.    4.3  Medium  2017-01-07  2014-02-20  View
7744  CVE-2011-0706  The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."    7.5  High  2017-01-07  2014-10-04  View
7743  CVE-2011-0702  The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to overwrite arbitrary files via a symlink attack on a /tmp/feh_ temporary file.    3.3  Low  2017-01-07  2011-02-15  View
7742  CVE-2011-0701  wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.    Medium  2017-01-07  2011-04-20  View
7741  CVE-2011-0700  Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.    3.5  Low  2017-01-07  2011-04-20  View

Page 16124 of 17672, showing 5 records out of 88360 total, starting on record 80616, ending on 80620

Actions