NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
9174  CVE-2011-2382  Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.    4.3  Medium  2017-01-07  2011-06-14  View
10198  CVE-2011-3588  The SSH configuration in the Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, disables the StrictHostKeyChecking option, which allows man-in-the-middle attackers to spoof kdump servers, and obtain sensitive core information, by using an arbitrary SSH key.    5.7  Medium  2017-01-07  2014-03-05  View
75734  CVE-1999-1084  The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.    4.6  Medium  2017-01-05  2016-10-17  View
10454  CVE-2011-3886  Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers out-of-bounds write operations.    6.8  Medium  2017-01-07  2012-11-06  View
10966  CVE-2011-4578  event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.    4.6  Medium  2017-01-07  2013-04-04  View

Page 16186 of 17672, showing 5 records out of 88360 total, starting on record 80926, ending on 80930

Actions