NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
44051  CVE-2012-2223  The xplat agent in Novell ZENworks Configuration Management (ZCM) 10.3.x before 10.3.4 and 11.x before 11.2 enables the HTTP TRACE method, which might make it easier for remote attackers to conduct cross-site tracing (XST) attacks via unspecified vectors.    4.3  Medium  2017-01-19  2012-04-11  View
71309  CVE-2004-0906  The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.    4.6  Medium  2017-07-18  2017-07-10  View
43408  CVE-2012-1508  The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.    7.2  High  2017-01-19  2013-11-02  View
35751  CVE-2014-8835  The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary"s Attributes key has the xpc_data data type, which allows attackers to execute arbitrary code by providing a crafted dictionary to sysmond, related to an "XPC type confusion" issue.    9.3  High  2017-01-19  2016-12-05  View
50578  CVE-2009-3374  The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."    7.5  High  2017-01-07  2010-08-21  View

Page 2584 of 17672, showing 5 records out of 88360 total, starting on record 12916, ending on 12920

Actions