NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46852 | CVE-2012-5815 | The Rackspace app 2.1.5 for iOS does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2013-02-07 | View | |
47364 | CVE-2009-0015 | Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management." | 2 | 4.9 | Medium | 2017-01-07 | 2011-03-07 | View | |
47620 | CVE-2009-0286 | Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter. | 2 | 2.6 | Low | 2017-01-07 | 2009-02-05 | View | |
47876 | CVE-2009-0545 | cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action. | 2 | 10 | High | 2017-01-07 | 2011-03-07 | View | |
48132 | CVE-2009-0815 | The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request. | 2 | 5 | Medium | 2017-01-07 | 2010-04-27 | View |
Page 326 of 17672, showing 5 records out of 88360 total, starting on record 1626, ending on 1630