NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
43245  CVE-2012-1248  app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.    5.1  Medium  2017-01-19  2012-05-29  View
26795  CVE-2015-5719  app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.    10  High  2017-01-19  2016-11-28  View
39832  CVE-2013-4182  app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.    7.5  High  2017-01-18  2013-09-17  View
23286  CVE-2015-0854  App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.    9.3  High  2017-01-19  2017-01-03  View
38560  CVE-2013-2506  app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.    Medium  2017-01-18  2013-03-18  View

Page 1306 of 17672, showing 5 records out of 88360 total, starting on record 6526, ending on 6530

Actions