NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5790  CVE-2008-6059  xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.    Medium  2017-01-03  2009-03-04  View
38259  CVE-2013-2161  XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.    7.5  High  2017-01-18  2013-10-07  View
23669  CVE-2015-1309  XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638.    Medium  2017-01-19  2015-01-25  View
34615  CVE-2014-7177  XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.    Medium  2017-01-19  2015-12-01  View
84855  CVE-2017-7457  XML External Entity via .AOP files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.    1.9  Low  2017-04-27  2017-04-21  View

Page 87 of 17672, showing 5 records out of 88360 total, starting on record 431, ending on 435

Actions