NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
78842  CVE-2001-1408  Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter.    Medium  2017-01-05  2008-09-05  View
13562  CVE-2010-2074  istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a "" character in a domain name in the (1) subject"s Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.    6.8  Medium  2017-01-18  2010-09-09  View
79098  CVE-2002-0082  The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.    7.5  High  2017-01-05  2016-10-17  View
13818  CVE-2010-2340  SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the by parameter in the msearch action.    6.8  Medium  2017-01-18  2010-06-21  View
79354  CVE-2002-0344  Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.    Medium  2017-01-05  2016-10-17  View

Page 17330 of 17672, showing 5 records out of 88360 total, starting on record 86646, ending on 86650

Actions