NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80100 | CVE-2002-1105 | Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
14820 | CVE-2010-3435 | The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user"s home directory. | 2 | 4.7 | Medium | 2017-01-18 | 2012-07-23 | View | |
80868 | CVE-2002-1917 | CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
15844 | CVE-2010-4595 | The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header. | 2 | 5 | Medium | 2017-01-18 | 2010-12-27 | View | |
81380 | CVE-2002-2429 | webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header. | 2 | 5 | Medium | 2017-01-05 | 2009-02-06 | View |
Page 16694 of 17672, showing 5 records out of 88360 total, starting on record 83466, ending on 83470