NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 46543 | CVE-2012-5348 | SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php. | 2 | 6.8 | Medium | 2017-01-19 | 2012-10-10 | View | |
| 46799 | CVE-2012-5705 | Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script or HTML via the "block names." | 2 | 2.1 | Low | 2017-01-19 | 2012-11-02 | View | |
| 47055 | CVE-2012-6107 | Apache Axis2/C does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 4.3 | Medium | 2017-01-19 | 2014-09-30 | View | |
| 47311 | CVE-2012-6635 | wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft. | 2 | 4 | Medium | 2017-01-19 | 2014-02-24 | View | |
| 47567 | CVE-2009-0232 | Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability." | 2 | 9.3 | High | 2017-01-07 | 2010-08-21 | View |
Page 14391 of 17672, showing 5 records out of 88360 total, starting on record 71951, ending on 71955