NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
76282  CVE-2000-0039  AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.    Medium  2017-01-05  2008-09-10  View
67738  CVE-2005-2029  amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.    7.5  High  2017-01-03  2008-09-05  View
72949  CVE-2004-2572  AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as () or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable.    Medium  2017-07-18  2017-07-10  View
46818  CVE-2012-5781  Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default JDK X509TrustManager.    5.8  Medium  2017-01-19  2012-11-06  View
46819  CVE-2012-5782  Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation of a certain "true" value.    5.8  Medium  2017-01-19  2012-11-19  View

Page 935 of 17672, showing 5 records out of 88360 total, starting on record 4671, ending on 4675

Actions