NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
9461  CVE-2011-2729  native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.    Medium  2017-01-07  2016-08-22  View
10229  CVE-2011-3639  The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.    4.3  Medium  2017-01-07  2012-02-24  View
76277  CVE-2000-0034  Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."    Medium  2017-01-05  2008-09-10  View
10997  CVE-2011-4610  JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."    Medium  2017-01-07  2014-03-05  View
76533  CVE-2000-0290  Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.    Medium  2017-01-05  2008-09-10  View

Page 17288 of 17672, showing 5 records out of 88360 total, starting on record 86436, ending on 86440

Actions