NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 80706 | CVE-2002-1755 | tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 78936 | CVE-2001-1505 | tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 75742 | CVE-1999-1092 | tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file. | 2 | 4.6 | Medium | 2017-01-05 | 2016-10-17 | View | |
| 32614 | CVE-2014-4663 | TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter. | 2 | 6.8 | Medium | 2017-01-19 | 2014-07-15 | View | |
| 10632 | CVE-2011-4106 | TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011. | 2 | 6.8 | Medium | 2017-01-07 | 2013-10-28 | View |
Page 2509 of 17672, showing 5 records out of 88360 total, starting on record 12541, ending on 12545