NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30475 | CVE-2014-1962 | Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue. | 2 | 5 | Medium | 2017-01-19 | 2014-02-21 | View | |
30731 | CVE-2014-2282 | The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted SS7 MTP3 packet. | 2 | 4.3 | Medium | 2017-01-19 | 2016-04-04 | View | |
30987 | CVE-2014-2597 | PCNetSoftware RAC Server 4.0.4 and 4.0.5 allows local users to cause a denial of service (disabled keyboard or crash) via a large input buffer to unspecified IOCTL requests in RACDriver.sys, which triggers a buffer over-read. | 2 | 4.9 | Medium | 2017-01-19 | 2014-04-21 | View | |
31243 | CVE-2014-2946 | Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML document. | 2 | 6.8 | Medium | 2017-01-19 | 2014-06-18 | View | |
31499 | CVE-2014-3296 | The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527. | 2 | 4 | Medium | 2017-01-19 | 2017-01-12 | View |
Page 692 of 17672, showing 5 records out of 88360 total, starting on record 3456, ending on 3460