NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46849 | CVE-2012-5812 | The ACRA library for Android does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2013-02-07 | View | |
47105 | CVE-2012-6312 | Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter in a video-lead-form action to wp-admin/admin.php. | 2 | 4.3 | Medium | 2017-01-19 | 2012-12-28 | View | |
47617 | CVE-2009-0283 | Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-02-05 | View | |
48385 | CVE-2009-1075 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. | 2 | 5 | Medium | 2017-01-07 | 2009-10-06 | View | |
49153 | CVE-2009-1888 | The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory. | 2 | 5.8 | Medium | 2017-01-07 | 2010-08-21 | View |
Page 66 of 17672, showing 5 records out of 88360 total, starting on record 326, ending on 330