NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
35816  CVE-2014-8987  Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.    3.5  Low  2017-01-19  2015-08-25  View
36072  CVE-2014-9358  Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."    6.4  Medium  2017-01-19  2014-12-30  View
36328  CVE-2014-9737  Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block.    5.8  Medium  2017-01-19  2015-07-08  View
36584  CVE-2013-0228  The xen_iret function in arch/x86/xen/xen-asm_32.S in the Linux kernel before 3.7.9 on 32-bit Xen paravirt_ops platforms does not properly handle an invalid value in the DS segment register, which allows guest OS users to gain guest OS privileges via a crafted application.    6.2  Medium  2017-01-18  2013-08-22  View
36840  CVE-2013-0505  IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.    5.5  Medium  2017-01-18  2013-03-21  View

Page 16258 of 17672, showing 5 records out of 88360 total, starting on record 81286, ending on 81290

Actions