NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
35823  CVE-2014-8994  The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).    3.6  Low  2017-01-19  2015-03-04  View
36079  CVE-2014-9367  Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to conduct cross-site scripting (XSS) attacks via a """ (single quote) in the scope parameter to do/view/TWiki/WebSearch.    4.3  Medium  2017-01-19  2015-01-02  View
36335  CVE-2014-9744  Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of ClientHello messages. NOTE: this identifier was SPLIT from CVE-2014-8628 per ADT3 due to different affected versions.    7.8  High  2017-01-19  2015-08-25  View
36591  CVE-2013-0235  The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.    6.4  Medium  2017-01-18  2013-07-08  View
36847  CVE-2013-0513  IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program, related to an "Unquoted Service Path Enumeration" vulnerability.    7.2  High  2017-01-18  2013-03-29  View

Page 16562 of 17672, showing 5 records out of 88360 total, starting on record 82806, ending on 82810

Actions