NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46070 | CVE-2012-4747 | Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to read (1) template (aka .tmpl) files, (2) other custom extension files under extensions/, or (3) custom documentation files under docs/ via a direct request. | 2 | 5 | Medium | 2017-01-19 | 2012-09-04 | View | |
46326 | CVE-2012-5112 | Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors. | 2 | 10 | High | 2017-01-19 | 2013-11-02 | View | |
46582 | CVE-2012-5422 | Unspecified vulnerability in Cisco IOS before 15.3(2)T on AS5400 devices allows remote authenticated users to cause a denial of service (spurious errors) via unknown vectors, aka Bug ID CSCub61009. | 2 | 6.8 | Medium | 2017-01-19 | 2014-04-23 | View | |
46838 | CVE-2012-5801 | The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function. | 2 | 5.8 | Medium | 2017-01-19 | 2012-11-05 | View | |
47094 | CVE-2012-6271 | Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitrary signed Xtras via a Shockwave movie that contains an Xtra URL, as demonstrated by a URL for an outdated Xtra. | 2 | 9.3 | High | 2017-01-19 | 2013-01-29 | View |
Page 16697 of 17672, showing 5 records out of 88360 total, starting on record 83481, ending on 83485