NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11314  CVE-2011-5054  kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an arbitrary valid PAM service name, a different vulnerability than CVE-2011-4122. NOTE: the vendor indicates that the possibility of resultant privilege escalation may be "a bit far-fetched."    6.9  Medium  2017-01-07  2012-01-31  View
76850  CVE-2000-0609  NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.    Medium  2017-01-05  2008-09-10  View
11570  CVE-2011-5318  Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify articles via a save_post action to admin/news/saveNEWS_ID/, (2) modify settings via a save_post action to admin/site/save2/, or (3) modify credentials via a save_post action to admin/usersite/save2/.    6.8  Medium  2017-01-07  2015-01-02  View
77106  CVE-2000-0872  explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.    Medium  2017-01-05  2008-09-05  View
12082  CVE-2010-0532  Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.    6.9  Medium  2017-01-18  2010-08-24  View

Page 1806 of 17672, showing 5 records out of 88360 total, starting on record 9026, ending on 9030

Actions