NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
31060  CVE-2014-2685  The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.    7.5  High  2017-01-19  2016-11-28  View
31828  CVE-2014-3677  Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.    7.5  High  2017-01-19  2014-11-13  View
34644  CVE-2014-7209  run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.    7.5  High  2017-01-19  2017-01-02  View
39764  CVE-2013-4091  The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the password (aka j_password) field on the secsphLogin.jsp login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.    7.5  High  2017-01-18  2013-07-01  View
43860  CVE-2012-2007  SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.    7.5  High  2017-01-19  2012-05-10  View

Page 2888 of 17672, showing 5 records out of 88360 total, starting on record 14436, ending on 14440

Actions