NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
27914 | CVE-2015-7231 | The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.5 for Drupal does not properly validate payments, which allows remote attackers to make a failed payment appear valid via a crafted URL, related to a "response from commweb." | 2 | 5 | Medium | 2017-01-19 | 2015-09-21 | View | |
28170 | CVE-2015-7675 | The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx. | 2 | 4 | Medium | 2017-01-19 | 2016-02-18 | View | |
28682 | CVE-2015-8563 | Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2015-12-17 | View | |
30474 | CVE-2014-1961 | Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack vectors. | 2 | 5 | Medium | 2017-01-19 | 2014-02-21 | View | |
30730 | CVE-2014-2281 | The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted NFS packet. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-12 | View |
Page 383 of 17672, showing 5 records out of 88360 total, starting on record 1911, ending on 1915