NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16311  CVE-2010-5076  QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject"s Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.    4.3  Medium  2017-01-18  2013-02-07  View
16312  CVE-2010-5077  server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.    7.8  High  2017-01-18  2014-10-28  View
16313  CVE-2010-5078  SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_version or (2) cms/silverstripe_version.    Medium  2017-01-18  2012-09-18  View
16314  CVE-2010-5079  SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.    Medium  2017-01-18  2012-09-18  View
16315  CVE-2010-5080  The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session via the HTTP referer logs on a server, aka "HTTP referer leakage."    6.8  Medium  2017-01-18  2012-08-27  View

Page 3263 of 17672, showing 5 records out of 88360 total, starting on record 16311, ending on 16315

Actions