NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10631 | CVE-2011-4105 | LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority. | 2 | 1.9 | Low | 2017-01-07 | 2014-03-07 | View | |
| 10632 | CVE-2011-4106 | TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011. | 2 | 6.8 | Medium | 2017-01-07 | 2013-10-28 | View | |
| 10633 | CVE-2011-4107 | The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack. | 2 | 4.3 | Medium | 2017-01-07 | 2012-11-06 | View | |
| 10634 | CVE-2011-4108 | The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack. | 2 | 4.3 | Medium | 2017-01-07 | 2016-08-22 | View | |
| 10635 | CVE-2011-4109 | Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check. | 2 | 9.3 | High | 2017-01-07 | 2013-09-11 | View |
Page 2127 of 17672, showing 5 records out of 88360 total, starting on record 10631, ending on 10635