NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
34848  CVE-2014-7484  The Coca-Cola FM Guatemala (aka com.enyetech.radio.coca_cola.fm_gu) application 2.0.41725 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    5.4  Medium  2017-01-19  2014-11-14  View
35104  CVE-2014-7809  Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.    6.8  Medium  2017-01-19  2016-10-25  View
35360  CVE-2014-8152  Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.    Medium  2017-01-19  2015-02-20  View
35616  CVE-2014-8610  AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which allows attackers to send stored SMS messages, and consequently transmit arbitrary new draft SMS messages or trigger additional per-message charges from a network operator for old messages, via a crafted application that broadcasts an intent with the com.android.mms.transaction.MESSAGE_SENT action, aka Bug 17671795.    3.3  Low  2017-01-19  2014-12-16  View
35872  CVE-2014-9059  lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.    4.3  Medium  2017-01-19  2015-09-03  View

Page 2566 of 17672, showing 5 records out of 88360 total, starting on record 12826, ending on 12830

Actions