NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
31787  CVE-2014-3623  Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.    Medium  2017-01-19  2015-04-24  View
32043  CVE-2014-3969  Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows local guest administrators to gain privileges via unspecified vectors.    7.4  High  2017-01-19  2016-10-19  View
32299  CVE-2014-4285  Unspecified vulnerability in the Oracle Applications Technology component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Reports Configuration.    4.3  Medium  2017-01-19  2015-11-05  View
32555  CVE-2014-4589  Cross-site scripting (XSS) vulnerability in uploader.php in the WP Silverlight Media Player (wp-media-player) plugin 0.8 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.    4.3  Medium  2017-01-19  2014-07-18  View
32811  CVE-2014-4939  SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the enl-add-new page to wp-admin/admin.php.    6.5  Medium  2017-01-19  2014-07-14  View

Page 2621 of 17672, showing 5 records out of 88360 total, starting on record 13101, ending on 13105

Actions