NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31225 | CVE-2014-2916 | Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack the authentication of administrators via a request to admin/. | 2 | 6.8 | Medium | 2017-01-19 | 2015-07-31 | View | |
31481 | CVE-2014-3277 | The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive user and group information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum77005. | 2 | 4 | Medium | 2017-01-19 | 2016-09-07 | View | |
31737 | CVE-2014-3560 | NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h. | 2 | 7.9 | High | 2017-01-19 | 2017-01-06 | View | |
31993 | CVE-2014-3906 | SQL injection vulnerability in OSK Advance-Flow 4.41 and earlier and Advance-Flow Forms 4.41 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2014-08-19 | View | |
32249 | CVE-2014-4233 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRREP. | 2 | 4 | Medium | 2017-01-19 | 2017-01-06 | View |
Page 16889 of 17672, showing 5 records out of 88360 total, starting on record 84441, ending on 84445