NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45800 | CVE-2012-4408 | course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation. | 2 | 5.5 | Medium | 2017-01-19 | 2012-09-19 | View | |
46056 | CVE-2012-4732 | Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, allows remote attackers to hijack the authentication of users for requests that toggle ticket bookmarks. | 2 | 6.8 | Medium | 2017-01-19 | 2013-03-01 | View | |
46312 | CVE-2012-5097 | Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.3.0, 11.1.1.5.0, and 11.1.2.0.0 allows remote attackers to affect integrity, related to OAM Webgate. | 2 | 4.3 | Medium | 2017-01-19 | 2013-10-10 | View | |
46568 | CVE-2012-5384 | Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5) $ext_users[] variables in view_entry.php, different vectors than CVE-2012-0846. | 2 | 4.3 | Medium | 2017-01-19 | 2012-10-22 | View | |
46824 | CVE-2012-5787 | The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2013-09-05 | View |
Page 16848 of 17672, showing 5 records out of 88360 total, starting on record 84236, ending on 84240