NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31219 | CVE-2014-2905 | fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions. | 2 | 6.9 | Medium | 2017-01-19 | 2014-05-05 | View | |
31475 | CVE-2014-3271 | The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug IDs CSCum85558, CSCum20949, CSCul61849, and CSCul71149. | 2 | 5 | Medium | 2017-01-19 | 2016-09-07 | View | |
31731 | CVE-2014-3553 | mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships. | 2 | 4.9 | Medium | 2017-01-19 | 2014-07-29 | View | |
31987 | CVE-2014-3900 | Cross-site scripting (XSS) vulnerability in admin/picture_modify.php in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the associate[] field, a different vulnerability than CVE-2014-4649. | 2 | 4.3 | Medium | 2017-01-19 | 2014-09-08 | View | |
32499 | CVE-2014-4518 | Cross-site scripting (XSS) vulnerability in xd_resize.php in the Contact Form by ContactMe.com plugin 2.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-02 | View |
Page 17225 of 17672, showing 5 records out of 88360 total, starting on record 86121, ending on 86125