NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35562 | CVE-2014-8536 | McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading unspecified error messages. | 2 | 2.1 | Low | 2017-01-19 | 2015-11-16 | View | |
35818 | CVE-2014-8989 | The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c. | 2 | 4.6 | Medium | 2017-01-19 | 2017-01-02 | View | |
36074 | CVE-2014-9361 | The LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal does not properly unset the authorized user role for certain users, which allows remote attackers with the pre-authorized role to gain privileges and possibly obtain sensitive information by accessing a Page Not Found (404) page. | 2 | 4.3 | Medium | 2017-01-19 | 2014-12-11 | View | |
36330 | CVE-2014-9739 | Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors involving internal fields. | 2 | 3.5 | Low | 2017-01-19 | 2015-07-08 | View | |
36586 | CVE-2013-0230 | Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method. | 2 | 10 | High | 2017-01-18 | 2016-12-07 | View |
Page 15872 of 17672, showing 5 records out of 88360 total, starting on record 79356, ending on 79360