NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
15590  CVE-2010-4335  The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.    7.5  High  2017-01-18  2011-01-22  View
35912  CVE-2014-9152  The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.    7.5  High  2017-01-19  2014-12-01  View
32978  CVE-2014-5247  The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API credentials, and other sensitive information by reading the file, related to the upgrade command.    2.1  Low  2017-01-19  2014-09-02  View
25128  CVE-2015-3238  The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.    5.8  Medium  2017-01-19  2016-12-02  View
54647  CVE-2007-2480  The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local traffic for daemons or other applications.    4.6  Medium  2017-01-07  2008-11-13  View

Page 2541 of 17672, showing 5 records out of 88360 total, starting on record 12701, ending on 12705

Actions