NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2949 | CVE-2008-3059 | member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to the "Settings - Account Information" tab. | 2 | 4 | Medium | 2017-01-03 | 2009-02-05 | View | |
| 8581 | CVE-2011-1687 | Best Practical Solutions RT 3.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote authenticated users to obtain sensitive information by using the search interface, as demonstrated by retrieving encrypted passwords. | 2 | 4 | Medium | 2017-01-07 | 2011-05-11 | View | |
| 21893 | CVE-2016-7572 | The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-10-04 | View | |
| 22917 | CVE-2015-0439 | Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756. | 2 | 4 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 26245 | CVE-2015-4929 | IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via a REST API request. | 2 | 4 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 14566 of 17672, showing 5 records out of 88360 total, starting on record 72826, ending on 72830