NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30950  CVE-2014-2534  /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.    4.9  Medium  2017-01-19  2014-04-01  View
31206  CVE-2014-2880  Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.    5.8  Medium  2017-01-19  2014-10-17  View
31462  CVE-2014-3251  The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition.    4.4  Medium  2017-01-19  2014-08-13  View
31974  CVE-2014-3885  Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.    4.3  Medium  2017-01-19  2014-07-22  View
32230  CVE-2014-4214  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP.    3.3  Low  2017-01-19  2017-01-06  View

Page 15946 of 17672, showing 5 records out of 88360 total, starting on record 79726, ending on 79730

Actions