NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 31660 | CVE-2014-3472 | The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors. | 2 | 4.9 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 22445 | CVE-2016-9756 | arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. | 2 | 2.1 | Low | 2017-01-19 | 2017-01-06 | View | |
| 31405 | CVE-2014-3160 | The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file. | 2 | 6.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 35245 | CVE-2014-7991 | The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 29358 | CVE-2014-0463 | Unspecified vulnerability in Oracle Java SE 8 allows remote attackers to affect confidentiality via unknown vectors related to Scripting, a different vulnerability than CVE-2014-0464. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-06 | View |
Page 2640 of 17672, showing 5 records out of 88360 total, starting on record 13196, ending on 13200