NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30694  CVE-2014-2236  Multiple cross-site scripting (XSS) vulnerabilities in Askbot before 0.7.49 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) tag or (2) user search forms.    4.3  Medium  2017-01-19  2015-07-30  View
30950  CVE-2014-2534  /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.    4.9  Medium  2017-01-19  2014-04-01  View
31206  CVE-2014-2880  Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.    5.8  Medium  2017-01-19  2014-10-17  View
31462  CVE-2014-3251  The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition.    4.4  Medium  2017-01-19  2014-08-13  View
31974  CVE-2014-3885  Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.    4.3  Medium  2017-01-19  2014-07-22  View

Page 16773 of 17672, showing 5 records out of 88360 total, starting on record 83861, ending on 83865

Actions