NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
43827 | CVE-2012-1969 | The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment. | 2 | 4.3 | Medium | 2017-01-19 | 2013-12-12 | View | |
44339 | CVE-2012-2603 | The server in CollabNet ScrumWorks Pro before 6.0 allows remote authenticated users to gain privileges and obtain sensitive information via a modified desktop client. | 2 | 6.5 | Medium | 2017-01-19 | 2012-06-28 | View | |
44595 | CVE-2012-2904 | player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via multiple "javascript:" sequences in the debug parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2012-05-31 | View | |
45363 | CVE-2012-3819 | Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial of service (daemon crash) via a long request. | 2 | 5 | Medium | 2017-01-19 | 2015-12-04 | View | |
46387 | CVE-2012-5177 | Cross-site scripting (XSS) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2012-12-19 | View |
Page 1859 of 17672, showing 5 records out of 88360 total, starting on record 9291, ending on 9295