NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
45812  CVE-2012-4421  The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.    Medium  2017-01-19  2012-09-17  View
46068  CVE-2012-4745  Cross-site scripting (XSS) vulnerability in admin/login.asp in Acuity CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.    4.3  Medium  2017-01-19  2012-09-04  View
46324  CVE-2012-5110  The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.    Medium  2017-01-19  2016-09-28  View
46580  CVE-2012-5417  Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote attackers to execute arbitrary commands via JBoss Application Server Remote Method Invocation (RMI) services, aka Bug ID CSCtz44924.    10  High  2017-01-19  2013-02-25  View
46836  CVE-2012-5799  The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.    5.8  Medium  2017-01-19  2012-11-06  View

Page 16911 of 17672, showing 5 records out of 88360 total, starting on record 84551, ending on 84555

Actions