NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46844 | CVE-2012-5807 | The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2012-11-06 | View | |
47100 | CVE-2012-6290 | SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands. | 2 | 6.5 | Medium | 2017-01-19 | 2014-03-11 | View | |
47356 | CVE-2009-0007 | Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms. | 2 | 9.3 | High | 2017-01-07 | 2012-02-29 | View | |
47612 | CVE-2009-0278 | Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View | |
47868 | CVE-2009-0536 | at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges. | 2 | 4.9 | Medium | 2017-01-07 | 2011-03-07 | View |
Page 17456 of 17672, showing 5 records out of 88360 total, starting on record 87276, ending on 87280