NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30707  CVE-2014-2250  The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors, a different vulnerability than CVE-2014-2251.    8.3  High  2017-01-19  2014-03-24  View
30963  CVE-2014-2558  The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a " (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.    6.5  Medium  2017-01-19  2014-05-07  View
31219  CVE-2014-2905  fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.    6.9  Medium  2017-01-19  2014-05-05  View
31475  CVE-2014-3271  The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug IDs CSCum85558, CSCum20949, CSCul61849, and CSCul71149.    Medium  2017-01-19  2016-09-07  View
31731  CVE-2014-3553  mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships.    4.9  Medium  2017-01-19  2014-07-29  View

Page 16923 of 17672, showing 5 records out of 88360 total, starting on record 84611, ending on 84615

Actions