NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
15094 | CVE-2010-3749 | The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a " (double quote) in an argument to the RecordClip method, aka "parameter injection." | 2 | 9.3 | High | 2017-01-18 | 2011-01-26 | View | |
80630 | CVE-2002-1677 | 14all.cgi 1.1p15 in mrtgconfig allows remote attackers to determine the physical path to the web root directory via a request with an invalid cfg parameter, which generates an error message that reveals the path. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
15350 | CVE-2010-4032 | Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 2 | 6.8 | Medium | 2017-01-18 | 2011-01-21 | View | |
80886 | CVE-2002-1935 | Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
15606 | CVE-2010-4351 | The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader. | 2 | 6.8 | Medium | 2017-01-18 | 2014-10-04 | View |
Page 16667 of 17672, showing 5 records out of 88360 total, starting on record 83331, ending on 83335