NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 44618 | CVE-2012-2927 | The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2012-08-13 | View | |
| 44874 | CVE-2012-3255 | Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2013-03-21 | View | |
| 45386 | CVE-2012-3847 | slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause a denial of service (resource consumption) via a long Unicode string, a different vulnerability than CVE-2012-3007. | 2 | 5 | Medium | 2017-01-19 | 2012-08-13 | View | |
| 45642 | CVE-2012-4196 | Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object. | 2 | 5 | Medium | 2017-01-19 | 2013-11-02 | View | |
| 46666 | CVE-2012-5543 | The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node"s author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source feed. | 2 | 4.3 | Medium | 2017-01-19 | 2012-12-04 | View |
Page 2684 of 17672, showing 5 records out of 88360 total, starting on record 13416, ending on 13420