NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 45023 | CVE-2012-3428 | The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt. | 2 | 4.3 | Medium | 2017-01-19 | 2013-01-08 | View | |
| 45279 | CVE-2012-3696 | CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that leverages improper WebSockets URI handling. | 2 | 4.3 | Medium | 2017-01-19 | 2013-03-21 | View | |
| 45535 | CVE-2012-4067 | Walrus in Eucalyptus before 3.2.2 allows remote attackers to cause a denial of service (memory, thread, and CPU consumption) via a crafted XML message containing a DTD, as demonstrated by a bucket-logging request. | 2 | 4.3 | Medium | 2017-01-19 | 2013-09-18 | View | |
| 45791 | CVE-2012-4399 | The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack. | 2 | 5 | Medium | 2017-01-19 | 2013-07-30 | View | |
| 46047 | CVE-2012-4712 | Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors. | 2 | 5 | Medium | 2017-01-19 | 2013-02-15 | View |
Page 15481 of 17672, showing 5 records out of 88360 total, starting on record 77401, ending on 77405