NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
43005 | CVE-2012-0960 | Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request. | 2 | 7.5 | High | 2017-01-19 | 2013-02-25 | View | |
43261 | CVE-2012-1293 | Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams" Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote attackers to inject arbitrary web script or HTML via the (1) to or (2) from parameters. | 2 | 4.3 | Medium | 2017-01-19 | 2012-10-30 | View | |
43517 | CVE-2012-1645 | The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php. | 2 | 2.6 | Low | 2017-01-19 | 2012-08-29 | View | |
43773 | CVE-2012-1912 | Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566. | 2 | 4.3 | Medium | 2017-01-19 | 2012-09-10 | View | |
44029 | CVE-2012-2190 | IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol. | 2 | 5 | Medium | 2017-01-19 | 2012-08-21 | View |
Page 17536 of 17672, showing 5 records out of 88360 total, starting on record 87676, ending on 87680