NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
11314 | CVE-2011-5054 | kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an arbitrary valid PAM service name, a different vulnerability than CVE-2011-4122. NOTE: the vendor indicates that the possibility of resultant privilege escalation may be "a bit far-fetched." | 2 | 6.9 | Medium | 2017-01-07 | 2012-01-31 | View | |
76850 | CVE-2000-0609 | NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
11570 | CVE-2011-5318 | Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify articles via a save_post action to admin/news/saveNEWS_ID/, (2) modify settings via a save_post action to admin/site/save2/, or (3) modify credentials via a save_post action to admin/usersite/save2/. | 2 | 6.8 | Medium | 2017-01-07 | 2015-01-02 | View | |
77106 | CVE-2000-0872 | explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
12082 | CVE-2010-0532 | Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse. | 2 | 6.9 | Medium | 2017-01-18 | 2010-08-24 | View |
Page 1806 of 17672, showing 5 records out of 88360 total, starting on record 9026, ending on 9030