NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30971 | CVE-2014-2573 | The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image. | 2 | 2.3 | Low | 2017-01-19 | 2014-03-26 | View | |
31227 | CVE-2014-2922 | The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an object obtained by unserializing a pathname, which allows remote attackers to conduct PHP object injection attacks and delete arbitrary files via vectors involving a Zend_Http_Response_Stream object. | 2 | 6.4 | Medium | 2017-01-19 | 2014-04-22 | View | |
31483 | CVE-2014-3279 | The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSCun39631 and CSCun39643. | 2 | 5 | Medium | 2017-01-19 | 2015-12-04 | View | |
31739 | CVE-2014-3562 | Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory. | 2 | 5 | Medium | 2017-01-19 | 2014-08-21 | View | |
31995 | CVE-2014-3908 | The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2014-09-02 | View |
Page 17025 of 17672, showing 5 records out of 88360 total, starting on record 85121, ending on 85125