NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45855 | CVE-2012-4472 | Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter. | 2 | 5.1 | Medium | 2017-01-19 | 2013-01-29 | View | |
46111 | CVE-2012-4837 | IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2013-03-05 | View | |
46367 | CVE-2012-5155 | Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for worker processes, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2013-01-16 | View | |
46623 | CVE-2012-5495 | python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back." | 2 | 5 | Medium | 2017-01-19 | 2014-10-02 | View | |
47135 | CVE-2012-6395 | Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to UNC share pathnames, which allows remote authenticated users to cause a denial of service (device crash) via unknown vectors, aka Bug ID CSCuc65775. | 2 | 6.3 | Medium | 2017-01-19 | 2013-02-02 | View |
Page 1148 of 17672, showing 5 records out of 88360 total, starting on record 5736, ending on 5740