NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
35915  CVE-2014-9155  Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.    Medium  2017-01-19  2014-12-05  View
46667  CVE-2012-5544  The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.    Medium  2017-01-19  2012-12-17  View
73036  CVE-2004-2659  Opera offers an Open button to verify that a user wishes to execute a downloaded file, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking Open via a request for a different mouse or keyboard action very shortly before the Open dialog appears. NOTE: this is a different issue than CVE-2005-2407.    Medium  2016-12-20  2008-09-05  View
86860  CVE-2016-8987  IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.    Medium  2017-06-18  2017-06-12  View
25164  CVE-2015-3289  OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.    Medium  2017-01-19  2016-12-02  View

Page 14480 of 17672, showing 5 records out of 88360 total, starting on record 72396, ending on 72400

Actions