NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35833 | CVE-2014-9004 | Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a member_profile action to index.php. | 2 | 4.3 | Medium | 2017-01-19 | 2014-11-20 | View | |
36089 | CVE-2014-9378 | Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted (1) name to the parse_line function in mdns_spoof/mdns_spoof.c or (2) base64 encoded password to the dissector_imap function in dissectors/ec_imap.c. | 2 | 7.5 | High | 2017-01-19 | 2016-12-30 | View | |
36345 | CVE-2014-9759 | Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information via a SOAP API request. | 2 | 5 | Medium | 2017-01-19 | 2016-12-02 | View | |
36601 | CVE-2013-0246 | The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2013-07-16 | View | |
36857 | CVE-2013-0532 | Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that cause a denial of service via malformed HTTP data. | 2 | 6.8 | Medium | 2017-01-18 | 2013-03-29 | View |
Page 17289 of 17672, showing 5 records out of 88360 total, starting on record 86441, ending on 86445