NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30707 | CVE-2014-2250 | The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors, a different vulnerability than CVE-2014-2251. | 2 | 8.3 | High | 2017-01-19 | 2014-03-24 | View | |
30963 | CVE-2014-2558 | The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a " (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function. | 2 | 6.5 | Medium | 2017-01-19 | 2014-05-07 | View | |
31219 | CVE-2014-2905 | fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions. | 2 | 6.9 | Medium | 2017-01-19 | 2014-05-05 | View | |
31475 | CVE-2014-3271 | The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug IDs CSCum85558, CSCum20949, CSCul61849, and CSCul71149. | 2 | 5 | Medium | 2017-01-19 | 2016-09-07 | View | |
31731 | CVE-2014-3553 | mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships. | 2 | 4.9 | Medium | 2017-01-19 | 2014-07-29 | View |
Page 16923 of 17672, showing 5 records out of 88360 total, starting on record 84611, ending on 84615