NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
9452 | CVE-2011-2719 | libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505. | 2 | 6.4 | Medium | 2017-01-07 | 2011-10-25 | View | |
9708 | CVE-2011-3011 | BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2011-09-21 | View | |
10476 | CVE-2011-3911 | Google Chrome before 16.0.912.63 does not properly handle PDF documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2012-01-26 | View | |
76268 | CVE-2000-0025 | IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
10988 | CVE-2011-4601 | family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition. | 2 | 5 | Medium | 2017-01-07 | 2013-11-02 | View |
Page 16956 of 17672, showing 5 records out of 88360 total, starting on record 84776, ending on 84780