NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
8369  CVE-2011-1428  Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.    5.8  Medium  2017-01-07  2011-03-22  View
71161  CVE-2004-0734  Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.    7.5  High  2017-07-18  2017-07-10  View
30754  CVE-2014-2321  web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.    10  High  2017-01-19  2014-03-11  View
13031  CVE-2010-1507  WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance"s image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.    Medium  2017-01-18  2010-09-06  View
39450  CVE-2013-3709  WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.    7.2  High  2017-01-18  2014-01-13  View

Page 260 of 17672, showing 5 records out of 88360 total, starting on record 1296, ending on 1300

Actions