NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27591  CVE-2015-6752  Cross-site scripting (XSS) vulnerability in the Search API Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when the search index is configured to use the HTML filter processor, allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the returned suggestions.    2.1  Low  2017-01-19  2015-09-01  View
32711  CVE-2014-4806  The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows local users to obtain sensitive information by reading this file.    2.1  Low  2017-01-19  2017-01-06  View
42183  CVE-2012-0034  The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.    2.1  Low  2017-01-19  2015-01-17  View
49351  CVE-2009-2089  The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a Migration Trace file.    2.1  Low  2017-01-07  2009-09-02  View
55751  CVE-2007-3601  vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users" calendar activities via a (1) home page or (2) event list view.    2.1  Low  2017-01-07  2008-11-15  View

Page 2145 of 17672, showing 5 records out of 88360 total, starting on record 10721, ending on 10725

Actions