NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69461  CVE-2005-3823  The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.    7.5  High  2017-01-03  2016-10-17  View
38242  CVE-2013-2143  The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.    6.5  Medium  2017-01-18  2014-04-17  View
32002  CVE-2014-3915  The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands via a (1) auth, (2) auth_session, (3) auth_simple, (4) add, (5) add_flat, (6) remove, (7) set_pwd, (8) add_permissions, (9) revoke_permissions, (10) runAsync, or (11) tsmRequest command.    10  High  2017-01-19  2014-06-12  View
48061  CVE-2009-0742  The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain sensitive information.    7.8  High  2017-01-07  2009-02-27  View
67469  CVE-2005-1745  The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.    4.6  Medium  2017-01-03  2011-03-07  View

Page 2826 of 17672, showing 5 records out of 88360 total, starting on record 14126, ending on 14130

Actions