NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47072 | CVE-2012-6130 | Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link. | 2 | 4.3 | Medium | 2017-01-19 | 2014-04-14 | View | |
47328 | CVE-2012-6657 | The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket. | 2 | 4.9 | Medium | 2017-01-19 | 2016-08-22 | View | |
47584 | CVE-2009-0250 | Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator"s password hash via a direct request for config/password. | 2 | 5 | Medium | 2017-01-07 | 2009-01-29 | View | |
48096 | CVE-2009-0777 | Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. | 2 | 5.8 | Medium | 2017-01-07 | 2012-01-05 | View | |
48608 | CVE-2009-1321 | Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-04-17 | View |
Page 16561 of 17672, showing 5 records out of 88360 total, starting on record 82801, ending on 82805