NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41466 | CVE-2013-6408 | The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407. | 2 | 6.4 | Medium | 2017-01-18 | 2014-07-17 | View | |
41978 | CVE-2013-7240 | Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter. | 2 | 5 | Medium | 2017-01-18 | 2014-02-25 | View | |
43002 | CVE-2012-0957 | The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from kernel stack memory via a uname system call in conjunction with a UNAME26 personality. | 2 | 4.9 | Medium | 2017-01-19 | 2013-08-21 | View | |
43258 | CVE-2012-1290 | Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the _loadPage parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2012-02-24 | View | |
43514 | CVE-2012-1642 | includes/linkchecker.pages.inc in the Link checker module 6.x-2.x before 6.x-2.5 for Drupal does not properly enforce access permissions on broken links, which allows remote attackers to obtain sensitive information via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2012-08-29 | View |
Page 17490 of 17672, showing 5 records out of 88360 total, starting on record 87446, ending on 87450