NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30999 | CVE-2014-2609 | The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116. | 2 | 10 | High | 2017-01-19 | 2014-06-26 | View | |
31255 | CVE-2014-2964 | Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4) flrp programs, which allows physically proximate attackers to gain privileges by sending a password over a serial line. | 2 | 6.9 | Medium | 2017-01-19 | 2014-08-15 | View | |
31511 | CVE-2014-3308 | Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985. | 2 | 6.4 | Medium | 2017-01-19 | 2017-01-12 | View | |
31767 | CVE-2014-3597 | Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049. | 2 | 6.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
32023 | CVE-2014-3944 | The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypass authentication via unspecified vectors. | 2 | 5.8 | Medium | 2017-01-19 | 2014-06-04 | View |
Page 1954 of 17672, showing 5 records out of 88360 total, starting on record 9766, ending on 9770