NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
15839  CVE-2010-4590  Cross-site scripting (XSS) vulnerability in HTTP Access Services (HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-18  2010-12-27  View
81375  CVE-2002-2424  Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag.    4.3  Medium  2017-01-05  2008-09-05  View
81631  CVE-2017-5368  ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).    6.8  Medium  2017-02-15  2017-02-09  View
16351  CVE-2010-5142  chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.    6.5  Medium  2017-01-18  2012-08-13  View
81887  CVE-2016-8686  The bm_new function in bitmap.h in potrace 1.13 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure.    6.8  Medium  2017-02-08  2017-02-05  View

Page 16510 of 17672, showing 5 records out of 88360 total, starting on record 82546, ending on 82550

Actions