NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
36083 | CVE-2014-9372 | Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename. | 2 | 6.4 | Medium | 2017-01-19 | 2015-02-17 | View | |
36339 | CVE-2014-9749 | Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability." | 2 | 4 | Medium | 2017-01-19 | 2015-11-09 | View | |
36595 | CVE-2013-0239 | Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element. | 2 | 5 | Medium | 2017-01-18 | 2013-06-04 | View | |
36851 | CVE-2013-0523 | IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access. | 2 | 4.3 | Medium | 2017-01-18 | 2013-06-24 | View | |
37363 | CVE-2013-1113 | Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager allows remote attackers to inject arbitrary web script or HTML via a crafted parameter value, aka Bug ID CSCue21042. | 2 | 4.3 | Medium | 2017-01-18 | 2013-02-02 | View |
Page 17228 of 17672, showing 5 records out of 88360 total, starting on record 86136, ending on 86140