NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69461 | CVE-2005-3823 | The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 38242 | CVE-2013-2143 | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account. | 2 | 6.5 | Medium | 2017-01-18 | 2014-04-17 | View | |
| 32002 | CVE-2014-3915 | The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands via a (1) auth, (2) auth_session, (3) auth_simple, (4) add, (5) add_flat, (6) remove, (7) set_pwd, (8) add_permissions, (9) revoke_permissions, (10) runAsync, or (11) tsmRequest command. | 2 | 10 | High | 2017-01-19 | 2014-06-12 | View | |
| 48061 | CVE-2009-0742 | The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain sensitive information. | 2 | 7.8 | High | 2017-01-07 | 2009-02-27 | View | |
| 67469 | CVE-2005-1745 | The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password. | 2 | 4.6 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 2826 of 17672, showing 5 records out of 88360 total, starting on record 14126, ending on 14130