NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
42034 | CVE-2013-7305 | fpw.php in e107 through 1.0.4 does not check the user_ban field, which makes it easier for remote attackers to reset passwords by sending a pwsubmit request and leveraging access to the e-mail account of a banned user. | 2 | 4.3 | Medium | 2017-01-18 | 2014-01-23 | View | |
42546 | CVE-2012-0451 | CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP headers. | 2 | 4.3 | Medium | 2017-01-19 | 2012-12-18 | View | |
42802 | CVE-2012-0719 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program. | 2 | 4.3 | Medium | 2017-01-19 | 2012-11-19 | View | |
43058 | CVE-2012-1024 | Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | 2 | 5 | Medium | 2017-01-19 | 2013-07-15 | View | |
43826 | CVE-2012-1968 | Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote attackers to obtain sensitive description information by reading the tooltip portions of an HTML e-mail message. | 2 | 4.3 | Medium | 2017-01-19 | 2013-10-03 | View |
Page 1825 of 17672, showing 5 records out of 88360 total, starting on record 9121, ending on 9125