NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
76782 | CVE-2000-0540 | JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
11502 | CVE-2011-5242 | tmhOAuth before 0.61 does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-07 | 2012-11-06 | View | |
77294 | CVE-2000-1060 | The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an "xhost + localhost" command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
77806 | CVE-2001-0328 | TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN. | 2 | 5 | Medium | 2017-01-05 | 2016-11-28 | View | |
13038 | CVE-2010-1514 | Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory. | 2 | 6 | Medium | 2017-01-18 | 2010-06-18 | View |
Page 17027 of 17672, showing 5 records out of 88360 total, starting on record 85131, ending on 85135