NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6231  CVE-2008-6500  Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.    4.3  Medium  2017-01-03  2009-03-20  View
72023  CVE-2004-1644  Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.    Medium  2017-07-18  2017-07-10  View
72279  CVE-2004-1901  Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.    4.6  Medium  2017-07-18  2017-07-10  View
6999  CVE-2008-7270  OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.    4.3  Medium  2017-01-03  2012-04-05  View
7511  CVE-2011-0447  Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage "combinations of browser plugins and HTTP redirects," a related issue to CVE-2011-0696.    6.8  Medium  2017-01-07  2012-07-06  View

Page 3125 of 17672, showing 5 records out of 88360 total, starting on record 15621, ending on 15625

Actions