NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45325 | CVE-2012-3743 | The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sensitive information via a crafted app that reads log files. | 2 | 5 | Medium | 2017-01-19 | 2013-03-25 | View | |
45581 | CVE-2012-4116 | The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffing the network, aka Bug ID CSCtr72970. | 2 | 4.3 | Medium | 2017-01-19 | 2013-10-21 | View | |
46861 | CVE-2012-5824 | Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, a different vulnerability than CVE-2009-4831. | 2 | 5.8 | Medium | 2017-01-19 | 2013-01-31 | View | |
47629 | CVE-2009-0295 | SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-02-05 | View | |
48141 | CVE-2009-0826 | BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request. | 2 | 5 | Medium | 2017-01-07 | 2009-03-06 | View |
Page 500 of 17672, showing 5 records out of 88360 total, starting on record 2496, ending on 2500