NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
44338 | CVE-2012-2602 | Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx. | 2 | 6.8 | Medium | 2017-01-19 | 2012-08-13 | View | |
44594 | CVE-2012-2903 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) target_language or (3) target_flag parameter to translate.php. | 2 | 4.3 | Medium | 2017-01-19 | 2012-05-22 | View | |
45106 | CVE-2012-3514 | OCaml Xml-Light Library before r234 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2014-02-11 | View | |
46130 | CVE-2012-4861 | The web server in InfoSphere Data Replication Dashboard in IBM InfoSphere Replication Server 9.7 and 10.1 through 10.1.0.4 allows remote authenticated users to list directories via a direct request for a directory URL. | 2 | 4 | Medium | 2017-01-19 | 2013-04-02 | View | |
46386 | CVE-2012-5176 | Cross-site scripting (XSS) vulnerability in KENT-WEB ACCESS REPORT 5.02 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to tag embedding. | 2 | 4.3 | Medium | 2017-01-19 | 2012-12-06 | View |
Page 1826 of 17672, showing 5 records out of 88360 total, starting on record 9126, ending on 9130