NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 46816 | CVE-2012-5777 | Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template. | 2 | 6.8 | Medium | 2017-01-19 | 2013-08-22 | View | |
| 47072 | CVE-2012-6130 | Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link. | 2 | 4.3 | Medium | 2017-01-19 | 2014-04-14 | View | |
| 47328 | CVE-2012-6657 | The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket. | 2 | 4.9 | Medium | 2017-01-19 | 2016-08-22 | View | |
| 47584 | CVE-2009-0250 | Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator"s password hash via a direct request for config/password. | 2 | 5 | Medium | 2017-01-07 | 2009-01-29 | View | |
| 47840 | CVE-2009-0508 | The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console. | 2 | 7.5 | High | 2017-01-07 | 2009-06-05 | View |
Page 15550 of 17672, showing 5 records out of 88360 total, starting on record 77746, ending on 77750