NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
31673  CVE-2014-3486  The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.    6.9  Medium  2017-01-19  2017-01-06  View
31929  CVE-2014-3830  Cross-site scripting (XSS) vulnerability in info.php in TomatoCart 1.1.8.6.1 allows remote attackers to inject arbitrary web script or HTML via the faqs_id parameter.    4.3  Medium  2017-01-19  2014-10-24  View
32697  CVE-2014-4784  IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not properly restrict use of FRAME elements, which allows remote attackers to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.    4.3  Medium  2017-01-30  2017-01-27  View
32953  CVE-2014-5204  wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.    6.8  Medium  2017-01-19  2015-11-25  View
33209  CVE-2014-5585  The Like4Like: Get Instagram Likes (aka com.bepop.bepop) application 2.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    5.4  Medium  2017-01-19  2014-11-09  View

Page 15180 of 17672, showing 5 records out of 88360 total, starting on record 75896, ending on 75900

Actions