NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
12257 | CVE-2010-0711 | Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete action in the ma2 parameter or (2) create administrators via the update action in the ma2 parameter. | 2 | 6.8 | Medium | 2017-01-18 | 2013-07-20 | View | |
12513 | CVE-2010-0977 | PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb. | 2 | 5 | Medium | 2017-01-18 | 2010-03-17 | View | |
78561 | CVE-2001-1126 | Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
13281 | CVE-2010-1781 | Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element. | 2 | 6.8 | Medium | 2017-01-18 | 2012-03-30 | View | |
78817 | CVE-2001-1383 | initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to conduct unauthorized operations on files. | 2 | 6.2 | Medium | 2017-01-05 | 2008-09-10 | View |
Page 16579 of 17672, showing 5 records out of 88360 total, starting on record 82891, ending on 82895