NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
36308  CVE-2014-9709  The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.    Medium  2017-01-19  2016-12-30  View
36564  CVE-2013-0208  The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users" volumes via a volume id in the block_device_mapping parameter.    6.5  Medium  2017-01-18  2013-02-14  View
36820  CVE-2013-0478  Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.    3.5  Low  2017-01-18  2013-02-21  View
37076  CVE-2013-0786  The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.    Medium  2017-01-18  2013-12-13  View
37332  CVE-2013-1069  Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.    2.1  Low  2017-01-18  2014-02-20  View

Page 14722 of 17672, showing 5 records out of 88360 total, starting on record 73606, ending on 73610

Actions