NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11503  CVE-2011-5243  TwitterOAuth does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.    5.8  Medium  2017-01-07  2012-11-06  View
74388  CVE-2003-1318  Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.    7.8  High  2017-01-03  2016-10-17  View
64632  CVE-2006-6071  TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.    High  2016-12-20  2011-03-07  View
61626  CVE-2006-2942  TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modified action attribute that references the Sandbox web instead of the user web, which can then be used to associate the user"s login name with the WikiName of a member of the TWikiAdminGroup.    5.1  Medium  2016-12-20  2011-03-07  View
60096  CVE-2006-1387  TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.    Medium  2016-12-20  2011-03-07  View

Page 2446 of 17672, showing 5 records out of 88360 total, starting on record 12226, ending on 12230

Actions