NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
8719 | CVE-2011-1839 | IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. | 2 | 5 | Medium | 2017-01-07 | 2011-05-02 | View | |
8975 | CVE-2011-2154 | login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for the loginsettings cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | 2 | 5 | Medium | 2017-01-07 | 2011-12-16 | View | |
74511 | CVE-2003-1441 | Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
9231 | CVE-2011-2449 | The TextXtra module in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | 2 | 10 | High | 2017-01-07 | 2012-02-14 | View | |
74767 | CVE-1999-0097 | The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character). | 2 | 10 | High | 2017-01-05 | 2008-09-09 | View |
Page 909 of 17672, showing 5 records out of 88360 total, starting on record 4541, ending on 4545