NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31191 | CVE-2014-2861 | Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the "alert" string. | 2 | 4.3 | Medium | 2017-01-19 | 2014-04-16 | View | |
31447 | CVE-2014-3207 | Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to pks/lookup/undefined1. | 2 | 4.3 | Medium | 2017-01-19 | 2014-05-09 | View | |
31703 | CVE-2014-3520 | OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request. | 2 | 6 | Medium | 2017-01-19 | 2014-10-28 | View | |
31959 | CVE-2014-3865 | Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++ header lines or (2) a +++ header line with a blank pathname. | 2 | 6.4 | Medium | 2017-01-19 | 2015-10-08 | View | |
32215 | CVE-2014-4199 | vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp. | 2 | 6.3 | Medium | 2017-01-19 | 2015-12-14 | View |
Page 16239 of 17672, showing 5 records out of 88360 total, starting on record 81191, ending on 81195