NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
74284  CVE-2003-1212  MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.    7.5  High  2017-07-18  2017-07-10  View
9260  CVE-2011-2481  Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.    4.6  Medium  2017-05-27  2017-05-22  View
75308  CVE-1999-0656  The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.    Medium  2017-07-18  2017-07-10  View
10028  CVE-2011-3376  org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.    4.4  Medium  2017-05-27  2017-05-22  View
78892  CVE-2001-1458  Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains ../ (dot dot) sequences and a null character.    Medium  2017-07-18  2017-07-10  View

Page 592 of 17672, showing 5 records out of 88360 total, starting on record 2956, ending on 2960

Actions