NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 13105 | CVE-2010-1585 | The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element. | 2 | 9.3 | High | 2017-01-18 | 2017-01-06 | View | |
| 78641 | CVE-2001-1206 | Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View | |
| 13361 | CVE-2010-1868 | The (1) sqlite_single_query and (2) sqlite_array_query functions in ext/sqlite/sqlite.c in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to execute arbitrary code by calling these functions with an empty SQL query, which triggers access of uninitialized memory. | 2 | 7.5 | High | 2017-01-18 | 2010-05-11 | View | |
| 13617 | CVE-2010-2130 | Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2010-06-03 | View | |
| 79153 | CVE-2002-0137 | CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configuration file. | 2 | 7.2 | High | 2017-01-05 | 2016-10-17 | View |
Page 2964 of 17672, showing 5 records out of 88360 total, starting on record 14816, ending on 14820