NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30680  CVE-2014-2212  The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.    Medium  2017-01-19  2014-04-02  View
30936  CVE-2014-2518  Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users.    6.8  Medium  2017-01-19  2017-01-06  View
31192  CVE-2014-2862  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unknown vectors.    6.5  Medium  2017-01-19  2014-04-16  View
31448  CVE-2014-3209  The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.    2.1  Low  2017-01-19  2014-11-17  View
31704  CVE-2014-3521  The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.    5.5  Medium  2017-01-19  2014-10-07  View

Page 15281 of 17672, showing 5 records out of 88360 total, starting on record 76401, ending on 76405

Actions