NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
7925 | CVE-2011-0899 | The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user. | 2 | 5 | Medium | 2017-01-07 | 2011-02-16 | View | |
73461 | CVE-2003-0327 | Sybase Adaptive Server Enterprise (ASE) 12.5 allows remote attackers to cause a denial of service (hang) via a remote password array with an invalid length, which triggers a heap-based buffer overflow. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
8437 | CVE-2011-1506 | The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-24 | View | |
74229 | CVE-2003-1157 | Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
74485 | CVE-2003-1415 | NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 17287 of 17672, showing 5 records out of 88360 total, starting on record 86431, ending on 86435