NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 46270 | CVE-2012-5055 | DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests. | 2 | 5 | Medium | 2017-01-19 | 2012-12-28 | View | |
| 46526 | CVE-2012-5330 | Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to calc.php, (2) chat.php, (3) register.php, or (4) index.php in libs/smarty_ajax/; or the (5) page parameter to libs/smarty_ajax/index.php. | 2 | 4.3 | Medium | 2017-01-19 | 2013-01-31 | View | |
| 46782 | CVE-2012-5684 | Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/. | 2 | 4.3 | Medium | 2017-01-19 | 2014-08-14 | View | |
| 47038 | CVE-2012-6088 | The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package. | 2 | 4.3 | Medium | 2017-01-19 | 2013-02-02 | View | |
| 47806 | CVE-2009-0474 | The web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to obtain "internal web page information" and "internal information about the module" via unspecified vectors. NOTE: this may overlap CVE-2002-1603. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View |
Page 15361 of 17672, showing 5 records out of 88360 total, starting on record 76801, ending on 76805