NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
35305  CVE-2014-8083  SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search alert subscription action.    7.5  High  2017-01-19  2015-01-06  View
35561  CVE-2014-8535  McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to bypass intended restriction on unspecified functionality via unknown vectors.    4.6  Medium  2017-01-19  2014-10-30  View
35817  CVE-2014-8988  MantisBT before 1.2.18 allows remote authenticated users to bypass the $g_download_attachments_threshold and $g_view_attachments_threshold restrictions and read attachments for private projects by leveraging access to a project that does not restrict access to attachments and a request to the download URL.    Medium  2017-01-19  2017-01-02  View
36073  CVE-2014-9360  XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted request.    6.4  Medium  2017-01-19  2014-12-11  View
36329  CVE-2014-9738  Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.    4.3  Medium  2017-01-19  2015-07-08  View

Page 15803 of 17672, showing 5 records out of 88360 total, starting on record 79011, ending on 79015

Actions