NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
43700  CVE-2012-1833  VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.    Medium  2017-01-19  2013-03-01  View
44212  CVE-2012-2401  Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.    Medium  2017-01-19  2014-05-05  View
44468  CVE-2012-2759  Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter in a lostpassword action to wp-login.php.    4.3  Medium  2017-01-19  2012-08-24  View
45236  CVE-2012-3652  WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.    6.8  Medium  2017-01-19  2013-11-02  View
45748  CVE-2012-4332  The ShareYourCart plugin 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors related to the SDK.    Medium  2017-01-19  2012-08-28  View

Page 15008 of 17672, showing 5 records out of 88360 total, starting on record 75036, ending on 75040

Actions