NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30475  CVE-2014-1962  Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.    Medium  2017-01-19  2014-02-21  View
30731  CVE-2014-2282  The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted SS7 MTP3 packet.    4.3  Medium  2017-01-19  2016-04-04  View
30987  CVE-2014-2597  PCNetSoftware RAC Server 4.0.4 and 4.0.5 allows local users to cause a denial of service (disabled keyboard or crash) via a large input buffer to unspecified IOCTL requests in RACDriver.sys, which triggers a buffer over-read.    4.9  Medium  2017-01-19  2014-04-21  View
31243  CVE-2014-2946  Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML document.    6.8  Medium  2017-01-19  2014-06-18  View
31499  CVE-2014-3296  The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.    Medium  2017-01-19  2017-01-12  View

Page 692 of 17672, showing 5 records out of 88360 total, starting on record 3456, ending on 3460

Actions