NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
43213  CVE-2012-1210  SQL injection vulnerability in pfile/file.php in Powie pFile 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-19  2012-02-24  View
43469  CVE-2012-1591  The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.    Medium  2017-01-19  2013-12-12  View
43725  CVE-2012-1858  The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."    4.3  Medium  2017-01-19  2013-03-06  View
43981  CVE-2012-2133  Use-after-free vulnerability in the Linux kernel before 3.3.6, when huge pages are enabled, allows local users to cause a denial of service (system crash) or possibly gain privileges by interacting with a hugetlbfs filesystem, as demonstrated by a umount operation that triggers improper handling of quota data.    Medium  2017-01-19  2012-08-13  View
44237  CVE-2012-2427  Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation.    10  High  2017-01-19  2012-05-28  View

Page 14627 of 17672, showing 5 records out of 88360 total, starting on record 73131, ending on 73135

Actions