NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46594 | CVE-2012-5456 | The Zoner AntiVirus Free application for Android does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, as demonstrated by a server used for updating virus signature files. | 2 | 4.3 | Medium | 2017-01-19 | 2015-11-04 | View | |
46850 | CVE-2012-5813 | The Android_Pusher library for Android does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2013-02-07 | View | |
47106 | CVE-2012-6313 | simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace. | 2 | 5 | Medium | 2017-01-19 | 2012-12-11 | View | |
47874 | CVE-2009-0543 | ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-09 | View | |
48386 | CVE-2009-1076 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. | 2 | 5 | Medium | 2017-01-07 | 2009-03-25 | View |
Page 105 of 17672, showing 5 records out of 88360 total, starting on record 521, ending on 525