NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
43212 | CVE-2012-1209 | Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2012-02-24 | View | |
43468 | CVE-2012-1590 | The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page. | 2 | 4 | Medium | 2017-01-19 | 2013-12-12 | View | |
43724 | CVE-2012-1857 | Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2013-03-06 | View | |
43980 | CVE-2012-2132 | libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection. | 2 | 5 | Medium | 2017-01-19 | 2013-02-14 | View | |
45260 | CVE-2012-3677 | WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1. | 2 | 6.8 | Medium | 2017-01-19 | 2013-11-02 | View |
Page 15848 of 17672, showing 5 records out of 88360 total, starting on record 79236, ending on 79240