NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30885  CVE-2014-2463  Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect integrity via unknown vectors related to Workspace Web Application, a different vulnerability than CVE-2014-4232.    4.3  Medium  2017-01-19  2016-11-21  View
31653  CVE-2014-3464  The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.    5.5  Medium  2017-01-19  2017-01-06  View
31909  CVE-2014-3807  Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) blog, (2) bloggeruser, or (3) bloggerpasswd parameter to private/manage/.    4.3  Medium  2017-01-19  2014-05-22  View
32421  CVE-2014-4430  CoreStorage in Apple OS X before 10.10 retains a volume"s encryption keys upon an eject action in the unlocked state, which makes it easier for physically proximate attackers to obtain cleartext data via a remount.    4.7  Medium  2017-01-19  2015-10-28  View
32677  CVE-2014-4758  IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.    Medium  2017-01-19  2015-11-06  View

Page 14477 of 17672, showing 5 records out of 88360 total, starting on record 72381, ending on 72385

Actions