NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
46652  CVE-2012-5526  CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.    Medium  2017-01-19  2016-12-07  View
46908  CVE-2012-5892  Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.    Medium  2017-01-19  2012-11-19  View
47164  CVE-2012-6462  Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request.    Medium  2017-01-19  2013-01-02  View
48188  CVE-2009-0873  The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."    6.8  Medium  2017-01-07  2009-04-02  View
48444  CVE-2009-1150  Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie.    4.3  Medium  2017-01-07  2009-07-15  View

Page 2189 of 17672, showing 5 records out of 88360 total, starting on record 10941, ending on 10945

Actions