NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
45867  CVE-2012-4485  Multiple cross-site scripting (XSS) vulnerabilities in the galleryformatter_field_formatter_view functiuon in galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2 for Drupal allow remote authenticated users with permissions to create a node or entity to inject arbitrary web script or HTML via the (1) title or (2) alt parameter.    4.3  Medium  2017-01-19  2013-07-19  View
46123  CVE-2012-4851  Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.    4.3  Medium  2017-01-19  2013-02-25  View
46379  CVE-2012-5169  Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote attackers to inject arbitrary web script or HTML via the (1) pathext, (2) popup, (3) framed, or (4) file parameter.    4.3  Medium  2017-01-19  2013-03-01  View
46635  CVE-2012-5507  AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.    4.3  Medium  2017-01-19  2014-10-02  View
46891  CVE-2012-5868  WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator"s logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.    2.6  Low  2017-01-19  2013-01-08  View

Page 3222 of 17672, showing 5 records out of 88360 total, starting on record 16106, ending on 16110

Actions