NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45812 | CVE-2012-4421 | The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature. | 2 | 4 | Medium | 2017-01-19 | 2012-09-17 | View | |
46068 | CVE-2012-4745 | Cross-site scripting (XSS) vulnerability in admin/login.asp in Acuity CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2012-09-04 | View | |
46324 | CVE-2012-5110 | The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-09-28 | View | |
46580 | CVE-2012-5417 | Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote attackers to execute arbitrary commands via JBoss Application Server Remote Method Invocation (RMI) services, aka Bug ID CSCtz44924. | 2 | 10 | High | 2017-01-19 | 2013-02-25 | View | |
46836 | CVE-2012-5799 | The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function. | 2 | 5.8 | Medium | 2017-01-19 | 2012-11-06 | View |
Page 16911 of 17672, showing 5 records out of 88360 total, starting on record 84551, ending on 84555