NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30450 | CVE-2014-1915 | Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the authentication of (1) administrators for requests that change the administrator password via an update action to sw/admin_change_password.php or (2) unspecified victims for requests that add a topic or blog entry to sw/add_topic.php. NOTE: vector 2 can be leveraged to bypass the authentication requirements for exploiting vector 1 in CVE-2014-1914. | 2 | 6.8 | Medium | 2017-01-19 | 2014-02-21 | View | |
30706 | CVE-2014-2249 | Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 2 | 5.8 | Medium | 2017-01-19 | 2014-03-26 | View | |
30962 | CVE-2014-2554 | OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element. | 2 | 4.3 | Medium | 2017-01-19 | 2014-04-24 | View | |
31218 | CVE-2014-2900 | wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-03 | View | |
31474 | CVE-2014-3270 | The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924. | 2 | 5 | Medium | 2017-01-19 | 2016-09-07 | View |
Page 16862 of 17672, showing 5 records out of 88360 total, starting on record 84306, ending on 84310