NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 46629 | CVE-2012-5501 | at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL. | 2 | 5 | Medium | 2017-01-19 | 2014-10-01 | View | |
| 46885 | CVE-2012-5861 | Multiple SQL injection vulnerabilities on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 allow remote attackers to execute arbitrary SQL commands via (1) the inverterselect parameter in a primo action to dettagliinverter.php or (2) the lingua parameter to changelanguagesession.php. | 2 | 7.5 | High | 2017-01-19 | 2013-02-02 | View | |
| 47141 | CVE-2012-6427 | Multiple SQL injection vulnerabilities in Carlo Gavazzi EOS-Box with firmware before 1.0.0.1080_2.1.10 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, a similar issue to CVE-2012-5861. | 2 | 7.5 | High | 2017-01-19 | 2012-12-24 | View | |
| 47397 | CVE-2009-0051 | ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. | 2 | 5 | Medium | 2017-01-07 | 2013-07-12 | View | |
| 47653 | CVE-2009-0321 | Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-04 | View |
Page 2272 of 17672, showing 5 records out of 88360 total, starting on record 11356, ending on 11360