NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45801 | CVE-2012-4409 | Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted file with a crafted header containing long salt data that is not properly handled during decryption. | 2 | 6.8 | Medium | 2017-01-19 | 2013-04-01 | View | |
46057 | CVE-2012-4733 | Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors. | 2 | 6 | Medium | 2017-01-19 | 2013-08-27 | View | |
46825 | CVE-2012-5788 | The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function. | 2 | 5.8 | Medium | 2017-01-19 | 2012-11-19 | View | |
48105 | CVE-2009-0787 | The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows local users to obtain portions of kernel memory. | 2 | 4.9 | Medium | 2017-01-07 | 2012-03-22 | View | |
48361 | CVE-2009-1051 | FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. | 2 | 5 | Medium | 2017-01-07 | 2009-04-02 | View |
Page 16880 of 17672, showing 5 records out of 88360 total, starting on record 84396, ending on 84400