NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
31258  CVE-2014-2967  Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.    10  High  2017-01-19  2014-07-07  View
44949  CVE-2012-3347  AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.    Medium  2017-01-19  2012-09-28  View
78967  CVE-2001-1536  Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.    Medium  2017-01-05  2008-09-05  View
73429  CVE-2003-0294  autohtml.php in php-proxima 6.0 and earlier allows remote attackers to read arbitrary files via the name parameter in a modload operation.    Medium  2017-01-03  2016-10-17  View
4491  CVE-2008-4677  autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating "I"m assuming that they"re using the same id and password on that unchanged hostname, deliberately."    4.3  Medium  2017-01-03  2009-04-01  View

Page 1462 of 17672, showing 5 records out of 88360 total, starting on record 7306, ending on 7310

Actions