NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35817 | CVE-2014-8988 | MantisBT before 1.2.18 allows remote authenticated users to bypass the $g_download_attachments_threshold and $g_view_attachments_threshold restrictions and read attachments for private projects by leveraging access to a project that does not restrict access to attachments and a request to the download URL. | 2 | 4 | Medium | 2017-01-19 | 2017-01-02 | View | |
36073 | CVE-2014-9360 | XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted request. | 2 | 6.4 | Medium | 2017-01-19 | 2014-12-11 | View | |
36329 | CVE-2014-9738 | Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-08 | View | |
36585 | CVE-2013-0229 | The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read. | 2 | 7.8 | High | 2017-01-18 | 2015-10-08 | View | |
36841 | CVE-2013-0506 | Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2013-03-21 | View |
Page 16319 of 17672, showing 5 records out of 88360 total, starting on record 81591, ending on 81595