NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30981 | CVE-2014-2587 | SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter). | 2 | 6.5 | Medium | 2017-01-19 | 2014-04-01 | View | |
31237 | CVE-2014-2938 | Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands. | 2 | 8.3 | High | 2017-01-19 | 2014-07-16 | View | |
31493 | CVE-2014-3290 | The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867. | 2 | 4.8 | Medium | 2017-01-19 | 2016-09-06 | View | |
31749 | CVE-2014-3572 | The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
32005 | CVE-2014-3920 | Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a save action to the default URI. | 2 | 6.8 | Medium | 2017-01-19 | 2014-07-07 | View |
Page 732 of 17672, showing 5 records out of 88360 total, starting on record 3656, ending on 3660