NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 45863 | CVE-2012-4481 | The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005. | 2 | 4.3 | Medium | 2017-01-19 | 2014-02-11 | View | |
| 46119 | CVE-2012-4846 | IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68. | 2 | 4.3 | Medium | 2017-01-19 | 2012-12-19 | View | |
| 46375 | CVE-2012-5164 | Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the term parameter to (1) autocomplete.php, (2) search/ajax/autosuggest.php, (3) livesuggest.php, or (4) save.php in frontend/modules/search/ajax. | 2 | 4.3 | Medium | 2017-01-19 | 2013-01-18 | View | |
| 46631 | CVE-2012-5503 | ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2014-10-01 | View | |
| 46887 | CVE-2012-5863 | ping.php on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in the ip_dominio parameter. | 2 | 10 | High | 2017-01-19 | 2013-02-02 | View |
Page 3051 of 17672, showing 5 records out of 88360 total, starting on record 15251, ending on 15255