NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45828 | CVE-2012-4443 | Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by leveraging cgi-bin write access. | 2 | 6.9 | Medium | 2017-01-19 | 2012-10-09 | View | |
46852 | CVE-2012-5815 | The Rackspace app 2.1.5 for iOS does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2013-02-07 | View | |
47364 | CVE-2009-0015 | Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management." | 2 | 4.9 | Medium | 2017-01-07 | 2011-03-07 | View | |
48132 | CVE-2009-0815 | The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request. | 2 | 5 | Medium | 2017-01-07 | 2010-04-27 | View | |
48388 | CVE-2009-1078 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact. | 2 | 4 | Medium | 2017-01-07 | 2009-10-06 | View |
Page 179 of 17672, showing 5 records out of 88360 total, starting on record 891, ending on 895