NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31227 | CVE-2014-2922 | The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an object obtained by unserializing a pathname, which allows remote attackers to conduct PHP object injection attacks and delete arbitrary files via vectors involving a Zend_Http_Response_Stream object. | 2 | 6.4 | Medium | 2017-01-19 | 2014-04-22 | View | |
31483 | CVE-2014-3279 | The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSCun39631 and CSCun39643. | 2 | 5 | Medium | 2017-01-19 | 2015-12-04 | View | |
31739 | CVE-2014-3562 | Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory. | 2 | 5 | Medium | 2017-01-19 | 2014-08-21 | View | |
31995 | CVE-2014-3908 | The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2014-09-02 | View | |
32251 | CVE-2014-4235 | Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, and 12.2.3 allows remote authenticated users to affect integrity via unknown vectors. | 2 | 3.5 | Low | 2017-01-19 | 2015-12-03 | View |
Page 17376 of 17672, showing 5 records out of 88360 total, starting on record 86876, ending on 86880