NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 43975 | CVE-2012-2126 | RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack. | 2 | 4.3 | Medium | 2017-01-19 | 2014-01-13 | View | |
| 44743 | CVE-2012-3117 | Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to HTTP. | 2 | 4 | Medium | 2017-01-19 | 2013-10-10 | View | |
| 44999 | CVE-2012-3402 | Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in GIMP 2.2.13 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted channels header value in a PSD image file, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2009-3909. | 2 | 6.8 | Medium | 2017-01-19 | 2013-05-14 | View | |
| 45255 | CVE-2012-3672 | WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1. | 2 | 6.8 | Medium | 2017-01-19 | 2013-11-02 | View | |
| 46791 | CVE-2012-5695 | Multiple cross-site request forgery (CSRF) vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allow remote attackers to hijack the authentication of administrators for requests that conduct (1) shell metacharacter or (2) SQL injection attacks or (3) send an SMS message. | 2 | 6.8 | Medium | 2017-01-19 | 2014-12-16 | View |
Page 15673 of 17672, showing 5 records out of 88360 total, starting on record 78361, ending on 78365