NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
12524 | CVE-2010-0988 | Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to improper handling of login failures by includes/login.php; and allow remote authenticated users to write to arbitrary files and execute arbitrary PHP code via vectors involving the (2) filename and (3) block parameters to view.php. | 2 | 6 | Medium | 2017-01-18 | 2010-03-29 | View | |
78060 | CVE-2001-0595 | Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
13036 | CVE-2010-1512 | Directory traversal vulnerability in aria2 before 1.9.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file. | 2 | 4.3 | Medium | 2017-01-18 | 2011-01-26 | View | |
78572 | CVE-2001-1137 | D-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram fragments. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
13548 | CVE-2010-2057 | shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack. | 2 | 5 | Medium | 2017-01-18 | 2010-11-19 | View |
Page 16958 of 17672, showing 5 records out of 88360 total, starting on record 84786, ending on 84790