NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30694 | CVE-2014-2236 | Multiple cross-site scripting (XSS) vulnerabilities in Askbot before 0.7.49 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) tag or (2) user search forms. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-30 | View | |
30950 | CVE-2014-2534 | /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow. | 2 | 4.9 | Medium | 2017-01-19 | 2014-04-01 | View | |
31206 | CVE-2014-2880 | Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin. | 2 | 5.8 | Medium | 2017-01-19 | 2014-10-17 | View | |
31462 | CVE-2014-3251 | The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition. | 2 | 4.4 | Medium | 2017-01-19 | 2014-08-13 | View | |
31974 | CVE-2014-3885 | Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-22 | View |
Page 16773 of 17672, showing 5 records out of 88360 total, starting on record 83861, ending on 83865