NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 31789 | CVE-2014-3627 | The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache. | 2 | 5 | Medium | 2017-01-19 | 2014-12-05 | View | |
| 32045 | CVE-2014-3971 | The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x before 2.6.2 allows remote attackers to cause a denial of service (daemon crash) by attempting authentication with an invalid X.509 client certificate. | 2 | 5 | Medium | 2017-01-19 | 2014-12-29 | View | |
| 32301 | CVE-2014-4287 | Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:CHARACTER SETS. | 2 | 4 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 32557 | CVE-2014-4591 | Cross-site scripting (XSS) vulnerability in picasa_upload.php in the WP-Picasa-Image plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-11 | View | |
| 32813 | CVE-2014-4941 | Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a full pathname in the rss parameter to proxy.php. | 2 | 5 | Medium | 2017-01-19 | 2014-07-14 | View |
Page 3254 of 17672, showing 5 records out of 88360 total, starting on record 16266, ending on 16270