NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47054 | CVE-2012-6106 | calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object. | 2 | 5.5 | Medium | 2017-01-19 | 2013-01-30 | View | |
47310 | CVE-2012-6634 | wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value. | 2 | 6.4 | Medium | 2017-01-19 | 2014-02-24 | View | |
48078 | CVE-2009-0759 | Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors. | 2 | 6.5 | Medium | 2017-01-07 | 2009-06-09 | View | |
48590 | CVE-2009-1303 | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree. | 2 | 5 | Medium | 2017-01-07 | 2010-08-21 | View | |
49102 | CVE-2009-1836 | Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack. | 2 | 6.8 | Medium | 2017-01-07 | 2010-08-21 | View |
Page 15920 of 17672, showing 5 records out of 88360 total, starting on record 79596, ending on 79600