NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30970 | CVE-2014-2572 | mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2014-03-24 | View | |
31226 | CVE-2014-2921 | The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via vectors involving a Zend_Pdf_ElementFactory_Proxy object and a pathname with a trailing character. | 2 | 7.5 | High | 2017-01-19 | 2014-04-22 | View | |
31482 | CVE-2014-3278 | The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to enumerate accounts by visiting an unspecified BVSMWeb web page, aka Bug IDs CSCun39619 and CSCun45572. | 2 | 5 | Medium | 2017-01-19 | 2015-12-04 | View | |
31738 | CVE-2014-3561 | The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes. | 2 | 2.1 | Low | 2017-01-19 | 2014-12-05 | View | |
31994 | CVE-2014-3907 | Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users. | 2 | 6.8 | Medium | 2017-01-19 | 2014-08-27 | View |
Page 16957 of 17672, showing 5 records out of 88360 total, starting on record 84781, ending on 84785