NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
42501 | CVE-2012-0392 | The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method. | 2 | 9.3 | High | 2017-01-19 | 2012-01-09 | View | |
42757 | CVE-2012-0668 | Buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding. | 2 | 9.3 | High | 2017-01-19 | 2016-05-06 | View | |
43013 | CVE-2012-0978 | Stack-based buffer overflow in npjp2.dll in LuraWave JP2 Browser Plug-In 1.1.1.11 and other versions before 2.1.1.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | 2 | 6.8 | Medium | 2017-01-19 | 2012-02-03 | View | |
43269 | CVE-2012-1311 | The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge and service outage) via crafted RSVP packets, aka Bug ID CSCts80643. | 2 | 7.8 | High | 2017-01-19 | 2012-08-15 | View | |
43525 | CVE-2012-1653 | Cross-site scripting (XSS) vulnerability in the Taxonomy Views Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to "views pages." | 2 | 3.5 | Low | 2017-01-19 | 2012-09-21 | View |
Page 741 of 17672, showing 5 records out of 88360 total, starting on record 3701, ending on 3705