NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
36239 | CVE-2014-9593 | Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call. | 2 | 5 | Medium | 2017-01-19 | 2015-01-16 | View | |
25138 | CVE-2015-3252 | Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server. | 2 | 6 | Medium | 2017-01-19 | 2016-02-12 | View | |
25137 | CVE-2015-3251 | Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls. | 2 | 4 | Medium | 2017-01-19 | 2016-02-12 | View | |
29047 | CVE-2014-0114 | Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1. | 2 | 7.5 | High | 2017-01-19 | 2017-01-06 | View | |
17354 | CVE-2016-1000031 | Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution | 2 | 7.5 | High | 2017-07-18 | 2017-07-17 | View |
Page 1265 of 17672, showing 5 records out of 88360 total, starting on record 6321, ending on 6325