NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
45065  CVE-2012-3472  The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET request.    6.4  Medium  2017-01-19  2012-08-13  View
45577  CVE-2012-4112  The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary commands via crafted command parameters within the command-line interface, aka Bug ID CSCtr43330.    6.8  Medium  2017-01-19  2013-10-21  View
45833  CVE-2012-4448  Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.    6.8  Medium  2017-01-19  2012-10-01  View
46601  CVE-2012-5471  The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.    6.5  Medium  2017-01-19  2013-06-20  View
46857  CVE-2012-5820  The developer-account sample code in Google AdMob does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.    5.8  Medium  2017-01-19  2013-02-07  View

Page 357 of 17672, showing 5 records out of 88360 total, starting on record 1781, ending on 1785

Actions