NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
42997 | CVE-2012-0948 | DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials. | 2 | 2.1 | Low | 2017-01-19 | 2012-06-12 | View | |
43253 | CVE-2012-1256 | The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a valid login name in the SSPI_HEADER parameter, to index.php. | 2 | 5 | Medium | 2017-01-19 | 2012-03-20 | View | |
43509 | CVE-2012-1636 | Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2012-10-02 | View | |
43765 | CVE-2012-1902 | show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file. | 2 | 4.3 | Medium | 2017-01-19 | 2012-11-06 | View | |
44021 | CVE-2012-2180 | The chaining functionality in the Distributed Relational Database Architecture (DRDA) module in IBM DB2 9.7 before FP6 and 9.8 before FP5 allows remote attackers to cause a denial of service (NULL pointer dereference, and resource consumption or daemon crash) via a crafted request. | 2 | 4.3 | Medium | 2017-01-19 | 2012-06-20 | View |
Page 16977 of 17672, showing 5 records out of 88360 total, starting on record 84881, ending on 84885