NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25832  CVE-2015-4374  Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a component name in the recipient (To) address of an email.    3.5  Low  2017-01-19  2015-06-26  View
35816  CVE-2014-8987  Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.    3.5  Low  2017-01-19  2015-08-25  View
38888  CVE-2013-2998  frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid action_code.    3.5  Low  2017-01-18  2014-05-27  View
44008  CVE-2012-2165  IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.    3.5  Low  2017-01-19  2012-08-20  View
56552  CVE-2007-4427  Unspecified vulnerability in the login page redirection logic in the Cache" Server Page (CSP) implementation in InterSystems Cache" 2007.1.0.369.0 and 2007.1.1.420.0 allows remote authenticated users to modify data on a server, related to encoding of certain parameter values by this redirection logic, aka MAK2116.    3.5  Low  2017-01-07  2008-11-15  View

Page 15113 of 17672, showing 5 records out of 88360 total, starting on record 75561, ending on 75565

Actions