NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
11278 | CVE-2011-5011 | Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack the authentication of Admins for requests that (1) set a New user to Admin via the cID parameter to a statusconfirm action in admin/customers.php and (2) grant permissions to users via the cID parameter to a save action in admin/accounting.php. | 2 | 6.8 | Medium | 2017-01-07 | 2014-01-07 | View | |
76814 | CVE-2000-0573 | The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command. | 2 | 10 | High | 2017-01-05 | 2016-10-17 | View | |
11534 | CVE-2011-5280 | Multiple stack-based buffer overflows in BOINC 6.13.x allow remote attackers to cause a denial of service (crash) via a long trickle-up to (1) client/cs_trickle.cpp or (2) db/db_base.cpp. | 2 | 5 | Medium | 2017-01-07 | 2014-06-03 | View | |
77070 | CVE-2000-0836 | Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
11790 | CVE-2010-0219 | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. | 2 | 10 | High | 2017-01-18 | 2013-05-09 | View |
Page 852 of 17672, showing 5 records out of 88360 total, starting on record 4256, ending on 4260