NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
29711 | CVE-2014-0867 | rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
30223 | CVE-2014-1607 | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future. | 2 | 4.3 | Medium | 2017-01-19 | 2014-10-18 | View | |
31759 | CVE-2014-3584 | The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service. | 2 | 5 | Medium | 2017-01-19 | 2014-11-04 | View | |
32271 | CVE-2014-4255 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS - Security and Policy. | 2 | 6.8 | Medium | 2017-01-19 | 2014-12-11 | View | |
32527 | CVE-2014-4557 | Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for Jigoshop (swipe-hq-checkout-for-jigoshop) plugin 3.1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-10 | View |
Page 562 of 17672, showing 5 records out of 88360 total, starting on record 2806, ending on 2810