NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45065 | CVE-2012-3472 | The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET request. | 2 | 6.4 | Medium | 2017-01-19 | 2012-08-13 | View | |
45577 | CVE-2012-4112 | The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary commands via crafted command parameters within the command-line interface, aka Bug ID CSCtr43330. | 2 | 6.8 | Medium | 2017-01-19 | 2013-10-21 | View | |
45833 | CVE-2012-4448 | Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action. | 2 | 6.8 | Medium | 2017-01-19 | 2012-10-01 | View | |
46601 | CVE-2012-5471 | The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout. | 2 | 6.5 | Medium | 2017-01-19 | 2013-06-20 | View | |
46857 | CVE-2012-5820 | The developer-account sample code in Google AdMob does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2013-02-07 | View |
Page 357 of 17672, showing 5 records out of 88360 total, starting on record 1781, ending on 1785