NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
43263  CVE-2012-1296  Multiple cross-site scripting (XSS) vulnerabilities in apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2-Beta and 1.1.x before 1.1.5-Beta allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body parameter to admin/preview.    4.3  Medium  2017-01-19  2012-08-27  View
43519  CVE-2012-1647  Multiple cross-site scripting (XSS) vulnerabilities in the "stand alone PHP application for the OSM Player," as used in the MediaFront module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal, allow remote attackers to inject arbitrary web script or HTML via (1) $_SERVER["HTTP_HOST"] or (2) $_SERVER["SCRIPT_NAME"] to players/osmplayer/player/OSMPlayer.php, (3) playlist parameter to players/osmplayer/player/getplaylist.php, and possibly other vectors related to $_SESSION.    4.3  Medium  2017-01-19  2012-08-29  View
43775  CVE-2012-1916  @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an executable extension, leading to the creation of an executable file under tmp/.    7.5  High  2017-01-19  2012-08-28  View
44031  CVE-2012-2192  The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.    4.9  Medium  2017-01-19  2013-03-21  View
44287  CVE-2012-2531  Microsoft Internet Information Services (IIS) 7.5 uses weak permissions for the Operational log, which allows local users to discover credentials by reading this file, aka "Password Disclosure Vulnerability."    2.1  Low  2017-01-19  2016-09-22  View

Page 15452 of 17672, showing 5 records out of 88360 total, starting on record 77256, ending on 77260

Actions