NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46847 | CVE-2012-5810 | The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default X509TrustManager. NOTE: this vulnerability was fixed in the summer of 2012, but the version number was not changed or is not known. | 2 | 5.8 | Medium | 2017-01-19 | 2016-03-22 | View | |
47103 | CVE-2012-6301 | The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SRC attribute of an IFRAME element. | 2 | 5 | Medium | 2017-01-19 | 2012-12-11 | View | |
47871 | CVE-2009-0540 | Cross-site scripting (XSS) vulnerability in Libero 5.3 SP5, and possibly other versions before 5.5 SP1, allows remote attackers to inject arbitrary web script or HTML via the search term field. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-09 | View | |
48383 | CVE-2009-1073 | nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field. | 2 | 4.9 | Medium | 2017-01-07 | 2009-04-08 | View | |
48639 | CVE-2009-1353 | Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon crash) via a long URI, related to http.c. | 2 | 5 | Medium | 2017-01-07 | 2009-04-29 | View |
Page 17665 of 17672, showing 5 records out of 88360 total, starting on record 88321, ending on 88325