NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 31060 | CVE-2014-2685 | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
| 31828 | CVE-2014-3677 | Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption. | 2 | 7.5 | High | 2017-01-19 | 2014-11-13 | View | |
| 34644 | CVE-2014-7209 | run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View | |
| 39764 | CVE-2013-4091 | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the password (aka j_password) field on the secsphLogin.jsp login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. | 2 | 7.5 | High | 2017-01-18 | 2013-07-01 | View | |
| 43860 | CVE-2012-2007 | SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2012-05-10 | View |
Page 2888 of 17672, showing 5 records out of 88360 total, starting on record 14436, ending on 14440