NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
42010 | CVE-2013-7277 | Multiple cross-site scripting (XSS) vulnerabilities in Andy"s PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to saa.php, (2) username parameter to login.php, or (3) keyword_list parameter to keysearch.php. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
42522 | CVE-2012-0419 | Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request. | 2 | 5 | Medium | 2017-01-19 | 2013-04-04 | View | |
43290 | CVE-2012-1361 | Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750. | 2 | 4.3 | Medium | 2017-01-19 | 2012-08-07 | View | |
43802 | CVE-2012-1944 | The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document. | 2 | 4.3 | Medium | 2017-01-19 | 2016-09-07 | View | |
44058 | CVE-2012-2236 | SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action. | 2 | 6.5 | Medium | 2017-01-19 | 2012-04-20 | View |
Page 960 of 17672, showing 5 records out of 88360 total, starting on record 4796, ending on 4800