NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
46847  CVE-2012-5810  The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default X509TrustManager. NOTE: this vulnerability was fixed in the summer of 2012, but the version number was not changed or is not known.    5.8  Medium  2017-01-19  2016-03-22  View
47103  CVE-2012-6301  The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SRC attribute of an IFRAME element.    Medium  2017-01-19  2012-12-11  View
47871  CVE-2009-0540  Cross-site scripting (XSS) vulnerability in Libero 5.3 SP5, and possibly other versions before 5.5 SP1, allows remote attackers to inject arbitrary web script or HTML via the search term field.    4.3  Medium  2017-01-07  2009-06-09  View
48383  CVE-2009-1073  nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.    4.9  Medium  2017-01-07  2009-04-08  View
48639  CVE-2009-1353  Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon crash) via a long URI, related to http.c.    Medium  2017-01-07  2009-04-29  View

Page 17665 of 17672, showing 5 records out of 88360 total, starting on record 88321, ending on 88325

Actions