NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
11529 | CVE-2011-5275 | The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for context-dependent users to gain privileges. | 2 | 7.5 | High | 2017-01-07 | 2014-03-21 | View | |
77065 | CVE-2000-0831 | Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
11785 | CVE-2010-0214 | The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the /admin/sign/DeviceSynch URI. | 2 | 5 | Medium | 2017-01-18 | 2011-07-19 | View | |
77321 | CVE-2000-1088 | The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 2 | 4.6 | Medium | 2017-01-05 | 2016-10-17 | View | |
12041 | CVE-2010-0488 | Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability." | 2 | 4.3 | Medium | 2017-01-18 | 2010-08-21 | View |
Page 630 of 17672, showing 5 records out of 88360 total, starting on record 3146, ending on 3150