NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17110  CVE-2016-0724  The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to obtain sensitive information via a web-service request.    Medium  2017-01-19  2016-08-17  View
18902  CVE-2016-2958  IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response.    Medium  2017-01-19  2016-11-30  View
25302  CVE-2015-3646  OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.    Medium  2017-01-19  2016-12-05  View
39126  CVE-2013-3300  The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users" sessions via invalid input data containing a < (less than) character.    Medium  2017-01-18  2013-07-29  View
45782  CVE-2012-4390  (1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors.    Medium  2017-01-19  2012-09-13  View

Page 3244 of 17672, showing 5 records out of 88360 total, starting on record 16216, ending on 16220

Actions