NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30530  CVE-2014-2024  Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/.    4.3  Medium  2017-01-19  2014-03-25  View
30786  CVE-2014-2356  Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.    Medium  2017-01-19  2014-08-04  View
31042  CVE-2014-2655  SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.    6.5  Medium  2017-01-19  2014-06-05  View
31298  CVE-2014-3021  IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.    Medium  2017-01-19  2014-10-21  View
31554  CVE-2014-3352  Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh84801.    4.3  Medium  2017-01-19  2017-01-06  View

Page 2397 of 17672, showing 5 records out of 88360 total, starting on record 11981, ending on 11985

Actions