NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
76781  CVE-2000-0539  Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID"s via the SessionServlet servlet.    6.4  Medium  2017-01-05  2008-09-05  View
11501  CVE-2011-5241  Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.    5.8  Medium  2017-01-07  2012-11-15  View
11757  CVE-2010-0182  The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.    4.3  Medium  2017-01-18  2012-09-14  View
77805  CVE-2001-0327  iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.    Medium  2017-01-05  2008-09-05  View
12525  CVE-2010-0989  Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f parameter.    5.5  Medium  2017-01-18  2010-03-29  View

Page 16992 of 17672, showing 5 records out of 88360 total, starting on record 84956, ending on 84960

Actions