NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
45827  CVE-2012-4442  Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.    4.7  Medium  2017-01-19  2012-10-08  View
46083  CVE-2012-4773  Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an add action to admin/accounts/add/.    6.8  Medium  2017-01-19  2013-06-04  View
46339  CVE-2012-5127  Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.    7.5  High  2017-01-19  2016-09-28  View
46595  CVE-2012-5458  VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application.    8.3  High  2017-01-19  2012-11-19  View
46851  CVE-2012-5814  Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.    5.8  Medium  2017-01-19  2013-02-07  View

Page 2430 of 17672, showing 5 records out of 88360 total, starting on record 12146, ending on 12150

Actions