NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45100 | CVE-2012-3508 | Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an HTML-formatted email. | 2 | 4.3 | Medium | 2017-01-19 | 2012-08-29 | View | |
45868 | CVE-2012-4486 | Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that switch the user to a subuser via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2012-11-06 | View | |
46124 | CVE-2012-4853 | Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger information disclosure. | 2 | 6.8 | Medium | 2017-01-19 | 2013-02-25 | View | |
46380 | CVE-2012-5170 | Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 2 | 5.8 | Medium | 2017-01-19 | 2013-02-02 | View | |
46636 | CVE-2012-5508 | The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope. | 2 | 5 | Medium | 2017-01-19 | 2014-11-04 | View |
Page 1614 of 17672, showing 5 records out of 88360 total, starting on record 8066, ending on 8070