NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41499 | CVE-2013-6443 | CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request. | 2 | 6.8 | Medium | 2017-01-18 | 2014-01-23 | View | |
41755 | CVE-2013-6903 | Cross-site scripting (XSS) vulnerability in a schedule component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2013-12-13 | View | |
42011 | CVE-2013-7278 | SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to default.asp. | 2 | 7.5 | High | 2017-01-18 | 2014-02-25 | View | |
42267 | CVE-2012-0124 | Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors. | 2 | 10 | High | 2017-01-19 | 2012-04-24 | View | |
42523 | CVE-2012-0420 | zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitrary directories, or possibly have unspecified other impact, via a pathname in the ZYPP_LOCKFILE_ROOT environment variable. | 2 | 4.4 | Medium | 2017-01-19 | 2013-12-02 | View |
Page 1663 of 17672, showing 5 records out of 88360 total, starting on record 8311, ending on 8315