NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41957 | CVE-2013-7196 | static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication. | 2 | 5.5 | Medium | 2017-01-18 | 2014-04-21 | View | |
43237 | CVE-2012-1240 | Cross-site scripting (XSS) vulnerability in the RECRUIT Dokodemo Rikunabi 2013 extension before 1.0.1 for Google Chrome allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2012-04-16 | View | |
44005 | CVE-2012-2162 | The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack. | 2 | 6.8 | Medium | 2017-01-19 | 2012-05-13 | View | |
44261 | CVE-2012-2490 | Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471. | 2 | 5 | Medium | 2017-01-19 | 2012-08-07 | View | |
44773 | CVE-2012-3147 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote attackers to affect integrity and availability, related to MySQL Client. | 2 | 6.4 | Medium | 2017-01-19 | 2013-12-05 | View |
Page 16744 of 17672, showing 5 records out of 88360 total, starting on record 83716, ending on 83720