NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
12016  CVE-2010-0460  Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertquestion action. NOTE: some of these details are obtained from third party information.    3.5  Low  2017-01-18  2010-01-31  View
12017  CVE-2010-0461  SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) category or (2) player action to index.php.    6.5  Medium  2017-01-18  2010-01-31  View
12018  CVE-2010-0462  Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.    6.5  Medium  2017-01-18  2012-01-26  View
12019  CVE-2010-0463  Horde IMP 4.3.6 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.    Medium  2017-01-18  2010-03-26  View
12020  CVE-2010-0464  Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.    Medium  2017-01-18  2015-08-24  View

Page 2404 of 17672, showing 5 records out of 88360 total, starting on record 12016, ending on 12020

Actions