NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 46652 | CVE-2012-5526 | CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 46908 | CVE-2012-5892 | Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3. | 2 | 5 | Medium | 2017-01-19 | 2012-11-19 | View | |
| 47164 | CVE-2012-6462 | Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request. | 2 | 5 | Medium | 2017-01-19 | 2013-01-02 | View | |
| 48188 | CVE-2009-0873 | The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other." | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-02 | View | |
| 48444 | CVE-2009-1150 | Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-15 | View |
Page 2189 of 17672, showing 5 records out of 88360 total, starting on record 10941, ending on 10945