NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
10231  CVE-2011-3645  Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to doccab/userprofile/editprofile.jsp, which selects the settings page of an arbitrary user.    7.5  High  2017-01-07  2012-02-13  View
10232  CVE-2011-3646  phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.    Medium  2017-01-07  2011-11-21  View
10233  CVE-2011-3647  The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.    9.3  High  2017-01-07  2012-01-26  View
10234  CVE-2011-3648  Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.    4.3  Medium  2017-01-07  2012-09-14  View
10235  CVE-2011-3649  Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.    2.6  Low  2017-01-07  2012-02-16  View

Page 2047 of 17672, showing 5 records out of 88360 total, starting on record 10231, ending on 10235

Actions