NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
8431 | CVE-2011-1500 | PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user"s home directory, which allows local users to obtain Pandora credentials by reading this file. | 2 | 2.1 | Low | 2017-01-07 | 2011-04-19 | View | |
8432 | CVE-2011-1501 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-1571. Reason: This candidate is a duplicate of CVE-2011-1571. Notes: All CVE users should reference CVE-2011-1571 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | 1 | 2017-01-07 | 2011-05-06 | View | |||
8433 | CVE-2011-1502 | Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue. | 2 | 4 | Medium | 2017-01-07 | 2011-05-31 | View | |
8434 | CVE-2011-1503 | The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL. | 2 | 3.5 | Low | 2017-01-07 | 2011-05-31 | View | |
8435 | CVE-2011-1504 | Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title. | 2 | 3.5 | Low | 2017-01-07 | 2011-05-31 | View |
Page 1687 of 17672, showing 5 records out of 88360 total, starting on record 8431, ending on 8435