NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
35353  CVE-2014-8144  Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authentication of unspecified victims for requests that read a user OAuth authorization code via unknown vectors.    6.8  Medium  2017-01-19  2015-02-24  View
35609  CVE-2014-8603  cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG["tarcompress"], (5) $_CONFIG["filename"], (6) $_CONFIG["exfile_tar"], (7) $_CONFIG[sqldump], (8) $_CONFIG["mysql_host"], (9) $_CONFIG["mysql_pass"], (10) $_CONFIG["mysql_user"], (11) $database_name, or (12) $sqlfile variable.    6.5  Medium  2017-01-19  2015-06-11  View
35865  CVE-2014-9045  The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requirements via a crafted password.    Medium  2017-01-19  2015-02-05  View
36121  CVE-2014-9418  The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users to cause a denial of service (memory overflow) via unspecified vectors.    2.1  Low  2017-01-19  2014-12-29  View
36377  CVE-2014-9796  app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate the page size in the kernel header, which allows attackers to bypass intended access restrictions via a crafted boot image, aka Android internal bug 28820722 and Qualcomm internal bug CR684756.    9.3  High  2017-01-19  2016-11-28  View

Page 1537 of 17672, showing 5 records out of 88360 total, starting on record 7681, ending on 7685

Actions