NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
11785 | CVE-2010-0214 | The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the /admin/sign/DeviceSynch URI. | 2 | 5 | Medium | 2017-01-18 | 2011-07-19 | View | |
77321 | CVE-2000-1088 | The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 2 | 4.6 | Medium | 2017-01-05 | 2016-10-17 | View | |
12041 | CVE-2010-0488 | Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability." | 2 | 4.3 | Medium | 2017-01-18 | 2010-08-21 | View | |
77577 | CVE-2001-0097 | The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
12297 | CVE-2010-0755 | PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute arbitrary PHP code via a URL in the langFile parameter. | 2 | 7.5 | High | 2017-01-18 | 2010-06-05 | View |
Page 555 of 17672, showing 5 records out of 88360 total, starting on record 2771, ending on 2775