NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
43529 | CVE-2012-1657 | Cross-site scripting (XSS) vulnerability in block_class.module in the Block Class module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the class name. | 2 | 2.1 | Low | 2017-01-19 | 2012-12-20 | View | |
43785 | CVE-2012-1926 | Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information. | 2 | 5 | Medium | 2017-01-19 | 2012-04-16 | View | |
44041 | CVE-2012-2206 | The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI. | 2 | 3.5 | Low | 2017-01-19 | 2012-08-17 | View | |
44297 | CVE-2012-2552 | Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2013-11-02 | View | |
44553 | CVE-2012-2860 | The date-picker implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site. | 2 | 6.8 | Medium | 2017-01-19 | 2012-08-13 | View |
Page 663 of 17672, showing 5 records out of 88360 total, starting on record 3311, ending on 3315