NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 33720 | CVE-2014-6139 | The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to bypass intended access restrictions and perform task-instance and process-instance searches by specifying a false value for the filterByCurrentUser parameter. | 2 | 4 | Medium | 2017-01-19 | 2015-02-17 | View | |
| 35768 | CVE-2014-8887 | IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to upload arbitrary GIFAR files, and consequently modify data, via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2015-06-08 | View | |
| 37816 | CVE-2013-1645 | Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the publication template path. | 2 | 4 | Medium | 2017-01-18 | 2013-09-26 | View | |
| 44984 | CVE-2012-3387 | Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check. | 2 | 4 | Medium | 2017-01-19 | 2012-07-24 | View | |
| 70329 | CVE-2005-4740 | IBM DB2 Universal Database (UDB) 810 before version 8 FixPak 10 allows remote authenticated users to cause a denial of service (db2jd service crash) by "connecting from a downlevel client." | 2 | 4 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 14638 of 17672, showing 5 records out of 88360 total, starting on record 73186, ending on 73190