NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
13574 | CVE-2010-2087 | Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object. | 2 | 4.3 | Medium | 2017-01-18 | 2013-01-28 | View | |
79110 | CVE-2002-0094 | config_converters.py in BSCW (Basic Support for Cooperative Work) 3.x and versions before 4.06 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name during filename conversion. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
13830 | CVE-2010-2353 | The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes. | 2 | 5 | Medium | 2017-01-18 | 2010-06-26 | View | |
79366 | CVE-2002-0356 | Vulnerability in XFS filesystem reorganizer (fsr_xfs) in SGI IRIX 6.5.10 and earlier allows local users to gain root privileges by overwriting critical system files. | 2 | 7.2 | High | 2017-01-05 | 2008-09-10 | View | |
14086 | CVE-2010-2637 | IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application. | 2 | 4.3 | Medium | 2017-01-18 | 2010-12-01 | View |
Page 429 of 17672, showing 5 records out of 88360 total, starting on record 2141, ending on 2145