NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
76781 | CVE-2000-0539 | Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID"s via the SessionServlet servlet. | 2 | 6.4 | Medium | 2017-01-05 | 2008-09-05 | View | |
11501 | CVE-2011-5241 | Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-07 | 2012-11-15 | View | |
11757 | CVE-2010-0182 | The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content. | 2 | 4.3 | Medium | 2017-01-18 | 2012-09-14 | View | |
77805 | CVE-2001-0327 | iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
12525 | CVE-2010-0989 | Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f parameter. | 2 | 5.5 | Medium | 2017-01-18 | 2010-03-29 | View |
Page 16992 of 17672, showing 5 records out of 88360 total, starting on record 84956, ending on 84960