NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
46324  CVE-2012-5110  The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.    Medium  2017-01-19  2016-09-28  View
46836  CVE-2012-5799  The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.    5.8  Medium  2017-01-19  2012-11-06  View
47092  CVE-2012-6153  http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.    4.3  Medium  2017-01-19  2016-08-22  View
48116  CVE-2009-0799  The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.    4.3  Medium  2017-01-07  2012-01-18  View
48628  CVE-2009-1342  Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form.    4.3  Medium  2017-01-07  2009-04-20  View

Page 17273 of 17672, showing 5 records out of 88360 total, starting on record 86361, ending on 86365

Actions