NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
45023  CVE-2012-3428  The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt.    4.3  Medium  2017-01-19  2013-01-08  View
45279  CVE-2012-3696  CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that leverages improper WebSockets URI handling.    4.3  Medium  2017-01-19  2013-03-21  View
45535  CVE-2012-4067  Walrus in Eucalyptus before 3.2.2 allows remote attackers to cause a denial of service (memory, thread, and CPU consumption) via a crafted XML message containing a DTD, as demonstrated by a bucket-logging request.    4.3  Medium  2017-01-19  2013-09-18  View
45791  CVE-2012-4399  The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.    Medium  2017-01-19  2013-07-30  View
46047  CVE-2012-4712  Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.    Medium  2017-01-19  2013-02-15  View

Page 15481 of 17672, showing 5 records out of 88360 total, starting on record 77401, ending on 77405

Actions