NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
73330  CVE-2003-0189  The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.    Medium  2017-07-18  2017-07-10  View
74098  CVE-2003-1026  Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the Travel Log Cross Domain Vulnerability.    9.3  High  2017-07-18  2017-07-10  View
74354  CVE-2003-1284  Sambar Server before 6.0 beta 6 allows remote attackers to obtain sensitive information via direct requests to the default scripts (1) environ.pl and (2) testcgi.exe.    Medium  2017-07-18  2017-07-10  View
81522  CVE-2017-3370  Vulnerability in the Oracle iSupport component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupport accessible data as well as unauthorized update, insert or delete access to some of Oracle iSupport accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).    5.8  Medium  2017-02-07  2017-01-31  View
82546  CVE-2017-3835  A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL Injection. More Information: CSCvb15627. Known Affected Releases: 1.4(0.908).    6.5  Medium  2017-03-18  2017-03-06  View

Page 16360 of 17672, showing 5 records out of 88360 total, starting on record 81796, ending on 81800

Actions