NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
42034  CVE-2013-7305  fpw.php in e107 through 1.0.4 does not check the user_ban field, which makes it easier for remote attackers to reset passwords by sending a pwsubmit request and leveraging access to the e-mail account of a banned user.    4.3  Medium  2017-01-18  2014-01-23  View
42546  CVE-2012-0451  CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP headers.    4.3  Medium  2017-01-19  2012-12-18  View
42802  CVE-2012-0719  Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program.    4.3  Medium  2017-01-19  2012-11-19  View
43058  CVE-2012-1024  Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.    Medium  2017-01-19  2013-07-15  View
43826  CVE-2012-1968  Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote attackers to obtain sensitive description information by reading the tooltip portions of an HTML e-mail message.    4.3  Medium  2017-01-19  2013-10-03  View

Page 1825 of 17672, showing 5 records out of 88360 total, starting on record 9121, ending on 9125

Actions