NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
76024  CVE-1999-1374  perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.    Medium  2017-01-05  2016-10-17  View
10744  CVE-2011-4275  Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a crafted CSV file, (4) a crafted copy-and-paste action, (5) the auth_user parameter in a suggest_pwd action to UI.php, (6) the c[menu] parameter to UniversalSearch.php, (7) the description parameter in a SearchFormToAdd_document_list action to UI.php, (8) the category parameter in an errors action to audit.php, or (9) the suggest_pwd parameter to UI.php.    4.3  Medium  2017-01-07  2011-12-12  View
76280  CVE-2000-0037  Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.    4.6  Medium  2017-01-05  2016-10-17  View
11000  CVE-2011-4613  The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.    4.6  Medium  2017-01-07  2014-02-24  View
76536  CVE-2000-0293  aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.    2.1  Low  2017-01-05  2008-09-10  View

Page 17204 of 17672, showing 5 records out of 88360 total, starting on record 86016, ending on 86020

Actions