NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
42731  CVE-2012-0641  CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-2011-3447.    Medium  2017-01-19  2012-03-09  View
43243  CVE-2012-1246  Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.    4.3  Medium  2017-01-19  2012-11-06  View
43499  CVE-2012-1626  SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.    Medium  2017-01-19  2012-10-15  View
43755  CVE-2012-1892  Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."    4.3  Medium  2017-01-19  2013-11-02  View
44267  CVE-2012-2498  Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.    Medium  2017-01-19  2012-08-07  View

Page 16942 of 17672, showing 5 records out of 88360 total, starting on record 84706, ending on 84710

Actions