NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
32378  CVE-2014-4383  The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device"s update status via a crafted Last-Modified HTTP response header.    4.3  Medium  2017-01-19  2017-01-06  View
58746  CVE-2007-6756  ZOLL Defibrillator / Monitor M Series, E Series, and R Series have a default password for System Configuration mode, which allows physically proximate attackers to modify device configuration and cause a denial of service (adverse human health effects).    4.9  Medium  2017-01-07  2017-01-06  View
23163  CVE-2015-0705  Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts, aka Bug ID CSCus97494.    6.8  Medium  2017-01-19  2017-01-06  View
29051  CVE-2014-0119  Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.    4.3  Medium  2017-01-19  2017-01-06  View
29307  CVE-2014-0412  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.    Medium  2017-01-19  2017-01-06  View

Page 2591 of 17672, showing 5 records out of 88360 total, starting on record 12951, ending on 12955

Actions