NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28364 | CVE-2015-8004 | MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not properly restrict access to revisions, which allows remote authenticated users with the viewsuppressed user right to remove revision suppressions via a crafted revisiondelete action, which returns a valid a change form. | 2 | 4 | Medium | 2017-01-19 | 2015-11-10 | View | |
| 32972 | CVE-2014-5239 | The Microsoft Outlook.com application before 7.8.2.12.49.7090 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 4 | Medium | 2017-01-19 | 2015-12-04 | View | |
| 35276 | CVE-2014-8023 | Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, does not properly select tunnel groups, which allows remote authenticated users to bypass intended resource-access restrictions via a crafted tunnel-group parameter, aka Bug ID CSCtz48533. | 2 | 4 | Medium | 2017-01-19 | 2015-11-27 | View | |
| 36812 | CVE-2013-0470 | HTTPD in IBM Netezza Performance Portal 1.0.2 allows remote authenticated users to list application directories containing asset files via a direct request to a directory URI, as demonstrated by listing image files. | 2 | 4 | Medium | 2017-01-18 | 2013-04-05 | View | |
| 43468 | CVE-2012-1590 | The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page. | 2 | 4 | Medium | 2017-01-19 | 2013-12-12 | View |
Page 3231 of 17672, showing 5 records out of 88360 total, starting on record 16151, ending on 16155