NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
21891  CVE-2016-7570  Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.    Medium  2017-01-19  2016-10-04  View
29059  CVE-2014-0129  badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.    Medium  2017-01-19  2014-03-24  View
30083  CVE-2014-1443  Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via a USER command with a specific length, possibly related to an out-of-bounds read.    Medium  2017-01-19  2014-05-02  View
35459  CVE-2014-8391  The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users" sessions via a large number of requests.    Medium  2017-01-19  2016-05-27  View
35971  CVE-2014-9225  The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors.    Medium  2017-01-19  2017-01-02  View

Page 14563 of 17672, showing 5 records out of 88360 total, starting on record 72811, ending on 72815

Actions