NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 42945 | CVE-2012-0883 | envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl. | 2 | 6.9 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 43457 | CVE-2012-1579 | The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-01-19 | 2012-09-10 | View | |
| 44225 | CVE-2012-2415 | Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 allows remote authenticated users to cause a denial of service or possibly have unspecified other impact via a series of KEYPAD_BUTTON_MESSAGE events. | 2 | 6.5 | Medium | 2017-01-19 | 2012-12-28 | View | |
| 45505 | CVE-2012-4027 | Directory traversal vulnerability in Tridium Niagara AX Framework allows remote attackers to read files outside of the intended images, nav, and px folders by leveraging incorrect permissions, as demonstrated by reading the config.bog file. | 2 | 5 | Medium | 2017-01-19 | 2012-07-17 | View | |
| 46017 | CVE-2012-4680 | Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing (backslash) character, allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in a URI. | 2 | 4.3 | Medium | 2017-01-19 | 2013-07-25 | View |
Page 15466 of 17672, showing 5 records out of 88360 total, starting on record 77326, ending on 77330