NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 45885 | CVE-2012-4503 | cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when client logging is disabled, which causes uninitialized data to be included in a reply. | 2 | 5 | Medium | 2017-01-19 | 2013-11-06 | View | |
| 46141 | CVE-2012-4873 | Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web script or HTML via the filename parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2012-09-10 | View | |
| 46397 | CVE-2012-5187 | The Weathernews Touch application 2.3.2 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files. | 2 | 4.3 | Medium | 2017-01-19 | 2013-02-07 | View | |
| 46909 | CVE-2012-5893 | Unrestricted file upload vulnerability in hava_upload.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading a file with a .php;.gif extension, then accessing it via a direct request to the file in tmp/files/. | 2 | 6.8 | Medium | 2017-01-19 | 2012-11-19 | View | |
| 47165 | CVE-2012-6463 | Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an unspecified sequence of loading of documents and loading of data: URLs. | 2 | 4.3 | Medium | 2017-01-19 | 2013-01-02 | View |
Page 2223 of 17672, showing 5 records out of 88360 total, starting on record 11111, ending on 11115