NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30950 | CVE-2014-2534 | /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow. | 2 | 4.9 | Medium | 2017-01-19 | 2014-04-01 | View | |
31206 | CVE-2014-2880 | Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin. | 2 | 5.8 | Medium | 2017-01-19 | 2014-10-17 | View | |
31462 | CVE-2014-3251 | The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition. | 2 | 4.4 | Medium | 2017-01-19 | 2014-08-13 | View | |
31974 | CVE-2014-3885 | Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-22 | View | |
32230 | CVE-2014-4214 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP. | 2 | 3.3 | Low | 2017-01-19 | 2017-01-06 | View |
Page 15946 of 17672, showing 5 records out of 88360 total, starting on record 79726, ending on 79730