NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
12661  CVE-2010-1127  Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.    Medium  2017-01-18  2010-03-29  View
12662  CVE-2010-1128  The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.    6.4  Medium  2017-01-18  2010-12-10  View
12663  CVE-2010-1129  The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.    7.5  High  2017-01-18  2010-08-31  View
12664  CVE-2010-1130  session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).    Medium  2017-01-18  2010-06-08  View
12665  CVE-2010-1131  JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the <object> substring.    4.3  Medium  2017-01-18  2010-06-08  View

Page 2533 of 17672, showing 5 records out of 88360 total, starting on record 12661, ending on 12665

Actions