NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31755 | CVE-2014-3578 | Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
32011 | CVE-2014-3932 | SQL injection vulnerability in the device registration component in wsf/webservice.php in CoSoSys Endpoint Protector 4 4.3.0.4 and 4.4.0.2 allows remote attackers to execute arbitrary SQL commands via unspecified parameters. | 2 | 7.5 | High | 2017-01-19 | 2014-06-03 | View | |
32267 | CVE-2014-4251 | Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0 and 12.1.2.0 allows remote authenticated users to affect integrity via vectors related to plugin 1.1. | 2 | 3.5 | Low | 2017-01-19 | 2014-12-11 | View | |
32523 | CVE-2014-4552 | Cross-site scripting (XSS) vulnerability in library/includes/payment/paypalexpress/DoDirectPayment.php in the Spotlight (spotlightyour) plugin 4.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the paymentType parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-10 | View | |
32779 | CVE-2014-4883 | resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets. | 2 | 4.3 | Medium | 2017-01-19 | 2015-01-08 | View |
Page 693 of 17672, showing 5 records out of 88360 total, starting on record 3461, ending on 3465