NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31454 | CVE-2014-3225 | Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile. | 2 | 4 | Medium | 2017-01-19 | 2014-05-16 | View | |
31710 | CVE-2014-3529 | The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-10 | View | |
31966 | CVE-2014-3876 | Multiple cross-site scripting (XSS) vulnerabilities in Frams" Fast File EXchange (F*EX, aka fex) before fex-20140530 allow remote attackers to inject arbitrary web script or HTML via the (1) akey parameter to rup or (2) disclaimer or (3) gm parameter to fuc. | 2 | 4.3 | Medium | 2017-01-19 | 2014-06-18 | View | |
32478 | CVE-2014-4494 | Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, which allows attackers to bypass intended first-launch restrictions by leveraging access to an enterprise distribution certificate for signing a crafted app. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-17 | View | |
32734 | CVE-2014-4829 | Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | 2 | 6.8 | Medium | 2017-01-19 | 2014-11-28 | View |
Page 16485 of 17672, showing 5 records out of 88360 total, starting on record 82421, ending on 82425