NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
42945  CVE-2012-0883  envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.    6.9  Medium  2017-01-19  2017-01-06  View
43457  CVE-2012-1579  The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information.    Medium  2017-01-19  2012-09-10  View
44225  CVE-2012-2415  Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 allows remote authenticated users to cause a denial of service or possibly have unspecified other impact via a series of KEYPAD_BUTTON_MESSAGE events.    6.5  Medium  2017-01-19  2012-12-28  View
45505  CVE-2012-4027  Directory traversal vulnerability in Tridium Niagara AX Framework allows remote attackers to read files outside of the intended images, nav, and px folders by leveraging incorrect permissions, as demonstrated by reading the config.bog file.    Medium  2017-01-19  2012-07-17  View
46017  CVE-2012-4680  Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing (backslash) character, allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in a URI.    4.3  Medium  2017-01-19  2013-07-25  View

Page 15466 of 17672, showing 5 records out of 88360 total, starting on record 77326, ending on 77330

Actions