NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
8369 | CVE-2011-1428 | Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API. | 2 | 5.8 | Medium | 2017-01-07 | 2011-03-22 | View | |
71161 | CVE-2004-0734 | Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
30754 | CVE-2014-2321 | web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials. | 2 | 10 | High | 2017-01-19 | 2014-03-11 | View | |
13031 | CVE-2010-1507 | WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance"s image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key. | 2 | 5 | Medium | 2017-01-18 | 2010-09-06 | View | |
39450 | CVE-2013-3709 | WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file. | 2 | 7.2 | High | 2017-01-18 | 2014-01-13 | View |
Page 260 of 17672, showing 5 records out of 88360 total, starting on record 1296, ending on 1300