NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46575 | CVE-2012-5394 | Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to hijack the authentication of users for requests that login via vectors involving image loading. | 2 | 6.8 | Medium | 2017-01-19 | 2013-12-16 | View | |
46831 | CVE-2012-5794 | The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2012-11-19 | View | |
47343 | CVE-2012-6698 | The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response. | 2 | 5 | Medium | 2017-01-19 | 2016-04-13 | View | |
47599 | CVE-2009-0265 | Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View | |
47855 | CVE-2009-0523 | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log. | 2 | 4.3 | Medium | 2017-01-07 | 2009-02-27 | View |
Page 17083 of 17672, showing 5 records out of 88360 total, starting on record 85411, ending on 85415