NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16715  CVE-2016-0222  IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors.    Medium  2017-01-19  2016-03-17  View
29003  CVE-2014-0060  PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.    Medium  2017-01-19  2017-01-06  View
30795  CVE-2014-2366  upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.    Medium  2017-01-19  2014-07-23  View
35915  CVE-2014-9155  Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.    Medium  2017-01-19  2014-12-05  View
46667  CVE-2012-5544  The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.    Medium  2017-01-19  2012-12-17  View

Page 3040 of 17672, showing 5 records out of 88360 total, starting on record 15196, ending on 15200

Actions