NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 42481 | CVE-2012-0365 | Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arbitrary directories via unspecified vectors, aka Bug ID CSCtw56009. | 2 | 9 | High | 2017-01-19 | 2012-03-06 | View | |
| 42737 | CVE-2012-0647 | WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header. | 2 | 5 | Medium | 2017-01-19 | 2012-03-13 | View | |
| 42993 | CVE-2012-0943 | debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-6648 has been assigned for the gdm-guest-session issue. | 2 | 2.1 | Low | 2017-01-19 | 2014-05-29 | View | |
| 43249 | CVE-2012-1252 | Cross-site scripting (XSS) vulnerability in RSSOwl before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a feed, a different vulnerability than CVE-2006-4760. | 2 | 4.3 | Medium | 2017-01-19 | 2012-06-05 | View | |
| 43505 | CVE-2012-1632 | Cross-site scripting (XSS) vulnerability in password_policy.admin.inc in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote authenticated users with administer policies permissions to inject arbitrary web script or HTML via the name parameter. | 2 | 2.1 | Low | 2017-01-19 | 2012-09-20 | View |
Page 14607 of 17672, showing 5 records out of 88360 total, starting on record 73031, ending on 73035