NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40465  CVE-2013-4995  Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information.    3.5  Low  2017-01-18  2016-12-30  View
43025  CVE-2012-0990  Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.    3.5  Low  2017-01-19  2012-02-08  View
81682  CVE-2017-5875  XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.    3.5  Low  2017-02-15  2017-02-09  View
30738  CVE-2014-2289  res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authenticated users to cause a denial of service (crash) via a SUBSCRIBE request without any Accept headers, which triggers an invalid pointer dereference.    3.5  Low  2017-01-19  2014-04-21  View
43026  CVE-2012-0991  Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.    3.5  Low  2017-01-19  2012-02-08  View

Page 2551 of 17672, showing 5 records out of 88360 total, starting on record 12751, ending on 12755

Actions