NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
44763  CVE-2012-3137  The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."    6.4  Medium  2017-01-19  2016-11-28  View
45019  CVE-2012-3424  The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.    Medium  2017-01-19  2013-02-06  View
45275  CVE-2012-3692  WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.    6.8  Medium  2017-01-19  2013-11-02  View
45531  CVE-2012-4063  The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.    Medium  2017-01-19  2013-03-25  View
45787  CVE-2012-4395  Cross-site scripting (XSS) vulnerability in index.php in ownCloud before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the redirect_url parameter.    4.3  Medium  2017-01-19  2012-09-06  View

Page 14857 of 17672, showing 5 records out of 88360 total, starting on record 74281, ending on 74285

Actions