NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
8719  CVE-2011-1839  IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.    Medium  2017-01-07  2011-05-02  View
8975  CVE-2011-2154  login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for the loginsettings cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.    Medium  2017-01-07  2011-12-16  View
74511  CVE-2003-1441  Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.    4.3  Medium  2017-01-03  2008-09-05  View
9231  CVE-2011-2449  The TextXtra module in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.    10  High  2017-01-07  2012-02-14  View
74767  CVE-1999-0097  The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).    10  High  2017-01-05  2008-09-09  View

Page 909 of 17672, showing 5 records out of 88360 total, starting on record 4541, ending on 4545

Actions