NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
36117  CVE-2014-9414  The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.    6.8  Medium  2017-01-19  2015-01-12  View
36373  CVE-2014-9792  arch/arm/mach-msm/ipc_router.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices uses an incorrect integer data type, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769399 and Qualcomm internal bug CR550606.    9.3  High  2017-01-19  2016-11-28  View
36629  CVE-2013-0276  ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.    4.3  Medium  2017-01-18  2013-06-05  View
36885  CVE-2013-0577  The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass intended access restrictions and create, modify, or delete documents or scripts via unspecified vectors.    5.2  Medium  2017-01-18  2013-10-10  View
37141  CVE-2013-0872  The swr_init function in libswresample/swresample.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid or unsupported (1) input or (2) output channel layout, related to an out-of-bounds array access.    10  High  2017-01-18  2016-12-02  View

Page 1822 of 17672, showing 5 records out of 88360 total, starting on record 9106, ending on 9110

Actions