NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46057 | CVE-2012-4733 | Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors. | 2 | 6 | Medium | 2017-01-19 | 2013-08-27 | View | |
46313 | CVE-2012-5098 | Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php. | 2 | 7.5 | High | 2017-01-19 | 2012-09-24 | View | |
46569 | CVE-2012-5385 | install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference. | 2 | 7.5 | High | 2017-01-19 | 2012-10-22 | View | |
46825 | CVE-2012-5788 | The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function. | 2 | 5.8 | Medium | 2017-01-19 | 2012-11-19 | View | |
47081 | CVE-2012-6142 | Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized. | 2 | 7.5 | High | 2017-01-19 | 2014-06-05 | View |
Page 16327 of 17672, showing 5 records out of 88360 total, starting on record 81631, ending on 81635