NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
43815 | CVE-2012-1957 | An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly handle EMBED elements within description elements in RSS feeds, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a feed. | 2 | 4.3 | Medium | 2017-01-19 | 2014-10-10 | View | |
44071 | CVE-2012-2253 | Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2013-04-18 | View | |
44327 | CVE-2012-2587 | Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted SRC attribute of (1) an IFRAME element or (2) a SCRIPT element. | 2 | 4.3 | Medium | 2017-01-19 | 2012-08-29 | View | |
44583 | CVE-2012-2892 | Unspecified vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to bypass the pop-up blocker via unknown vectors. | 2 | 5 | Medium | 2017-01-19 | 2013-11-02 | View | |
45095 | CVE-2012-3503 | The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token. | 2 | 6.5 | Medium | 2017-01-19 | 2013-03-21 | View |
Page 1445 of 17672, showing 5 records out of 88360 total, starting on record 7221, ending on 7225