NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
80706  CVE-2002-1755  tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.    Medium  2017-07-18  2017-07-10  View
78936  CVE-2001-1505  tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.    Medium  2017-07-18  2017-07-10  View
75742  CVE-1999-1092  tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.    4.6  Medium  2017-01-05  2016-10-17  View
32614  CVE-2014-4663  TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter.    6.8  Medium  2017-01-19  2014-07-15  View
10632  CVE-2011-4106  TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011.    6.8  Medium  2017-01-07  2013-10-28  View

Page 2509 of 17672, showing 5 records out of 88360 total, starting on record 12541, ending on 12545

Actions