NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
7925  CVE-2011-0899  The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user.    Medium  2017-01-07  2011-02-16  View
73461  CVE-2003-0327  Sybase Adaptive Server Enterprise (ASE) 12.5 allows remote attackers to cause a denial of service (hang) via a remote password array with an invalid length, which triggers a heap-based buffer overflow.    Medium  2017-07-18  2017-07-10  View
8437  CVE-2011-1506  The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411. NOTE: some of these details are obtained from third party information.    6.8  Medium  2017-01-07  2011-03-24  View
74229  CVE-2003-1157  Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.    4.3  Medium  2017-07-18  2017-07-10  View
74485  CVE-2003-1415  NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.    6.8  Medium  2017-01-03  2008-09-05  View

Page 17287 of 17672, showing 5 records out of 88360 total, starting on record 86431, ending on 86435

Actions