NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35792 | CVE-2014-8921 | The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message. | 2 | 4.3 | Medium | 2017-01-19 | 2015-03-03 | View | |
36048 | CVE-2014-9331 | Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do. | 2 | 6.8 | Medium | 2017-01-19 | 2015-02-04 | View | |
36560 | CVE-2013-0204 | settings/personal.php in ownCloud 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via crafted mount point settings. | 2 | 4.6 | Medium | 2017-01-18 | 2014-06-04 | View | |
36816 | CVE-2013-0474 | The Manual Explore browser plug-in in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to discover test Platform Authentication credentials via a crafted web site. | 2 | 4.3 | Medium | 2017-01-18 | 2013-03-29 | View | |
37328 | CVE-2013-1065 | backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288. | 2 | 4.6 | Medium | 2017-01-18 | 2013-10-04 | View |
Page 15985 of 17672, showing 5 records out of 88360 total, starting on record 79921, ending on 79925