NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35827 | CVE-2014-8998 | lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.php, which is processed by the preg_replace function with the eval switch. | 2 | 6.5 | Medium | 2017-01-19 | 2014-11-20 | View | |
36083 | CVE-2014-9372 | Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename. | 2 | 6.4 | Medium | 2017-01-19 | 2015-02-17 | View | |
36339 | CVE-2014-9749 | Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability." | 2 | 4 | Medium | 2017-01-19 | 2015-11-09 | View | |
36595 | CVE-2013-0239 | Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element. | 2 | 5 | Medium | 2017-01-18 | 2013-06-04 | View | |
36851 | CVE-2013-0523 | IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access. | 2 | 4.3 | Medium | 2017-01-18 | 2013-06-24 | View |
Page 16927 of 17672, showing 5 records out of 88360 total, starting on record 84631, ending on 84635