NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 12016 | CVE-2010-0460 | Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertquestion action. NOTE: some of these details are obtained from third party information. | 2 | 3.5 | Low | 2017-01-18 | 2010-01-31 | View | |
| 12017 | CVE-2010-0461 | SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) category or (2) player action to index.php. | 2 | 6.5 | Medium | 2017-01-18 | 2010-01-31 | View | |
| 12018 | CVE-2010-0462 | Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function. | 2 | 6.5 | Medium | 2017-01-18 | 2012-01-26 | View | |
| 12019 | CVE-2010-0463 | Horde IMP 4.3.6 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests. | 2 | 5 | Medium | 2017-01-18 | 2010-03-26 | View | |
| 12020 | CVE-2010-0464 | Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests. | 2 | 5 | Medium | 2017-01-18 | 2015-08-24 | View |
Page 2404 of 17672, showing 5 records out of 88360 total, starting on record 12016, ending on 12020