NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5790 | CVE-2008-6059 | xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. | 2 | 5 | Medium | 2017-01-03 | 2009-03-04 | View | |
38259 | CVE-2013-2161 | XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name. | 2 | 7.5 | High | 2017-01-18 | 2013-10-07 | View | |
23669 | CVE-2015-1309 | XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638. | 2 | 5 | Medium | 2017-01-19 | 2015-01-25 | View | |
34615 | CVE-2014-7177 | XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/. | 2 | 4 | Medium | 2017-01-19 | 2015-12-01 | View | |
84855 | CVE-2017-7457 | XML External Entity via .AOP files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure. | 2 | 1.9 | Low | 2017-04-27 | 2017-04-21 | View |
Page 87 of 17672, showing 5 records out of 88360 total, starting on record 431, ending on 435