NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30742 | CVE-2014-2301 | OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/. | 2 | 5 | Medium | 2017-01-19 | 2014-05-13 | View | |
31254 | CVE-2014-2963 | Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote attackers to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_middleName parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-10 | View | |
31510 | CVE-2014-3307 | The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513. | 2 | 6.8 | Medium | 2017-01-19 | 2015-12-03 | View | |
31766 | CVE-2014-3596 | The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
32534 | CVE-2014-4568 | Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-10 | View |
Page 813 of 17672, showing 5 records out of 88360 total, starting on record 4061, ending on 4065