NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10656 | CVE-2011-4139 | Django before 1.2.7 and 1.3.x before 1.3.1 uses a request"s HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poisoning attacks via a crafted request. | 2 | 5 | Medium | 2017-01-07 | 2012-01-26 | View | |
| 10657 | CVE-2011-4140 | The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers to trigger unauthenticated forged requests via vectors involving a DNS CNAME record and a web page containing JavaScript code. | 2 | 6.8 | Medium | 2017-01-07 | 2012-01-26 | View | |
| 10658 | CVE-2011-4141 | Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Software Token file. | 2 | 9.3 | High | 2017-01-07 | 2011-12-19 | View | |
| 10659 | CVE-2011-4142 | The Web Search feature in EMC SourceOne Email Management 6.5 before 6.5.2.4033, 6.6 before 6.6.1.2194, and 6.7 before 6.7.2.2033 places cleartext credentials in log files, which allows local users to obtain sensitive information by reading these files. | 2 | 2.1 | Low | 2017-01-07 | 2012-01-19 | View | |
| 10660 | CVE-2011-4143 | EMC RSA enVision 4.0 before SP4 P5 and 4.1 before P3 allows remote attackers to obtain sensitive information about environment variables in the web system via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2012-02-06 | View |
Page 2132 of 17672, showing 5 records out of 88360 total, starting on record 10656, ending on 10660