NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
14226  CVE-2010-2791  mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.    Medium  2017-01-18  2013-10-10  View
14227  CVE-2010-2792  Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.    3.3  Low  2017-01-18  2011-01-11  View
14228  CVE-2010-2793  Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.    6.8  Medium  2017-01-18  2013-01-16  View
14229  CVE-2010-2794  The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.    3.3  Low  2017-01-18  2010-09-08  View
14230  CVE-2010-2795  phpCAS before 1.1.2 allows remote authenticated users to hijack sessions via a query string containing a crafted ticket value.    Medium  2017-01-18  2011-03-01  View

Page 2846 of 17672, showing 5 records out of 88360 total, starting on record 14226, ending on 14230

Actions