NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28187  CVE-2015-7706  Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password.    4.3  Medium  2017-01-19  2016-01-13  View
28443  CVE-2015-8124  Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.    6.8  Medium  2017-01-19  2016-12-07  View
30235  CVE-2014-1626  XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.    Medium  2017-01-19  2014-01-27  View
30491  CVE-2014-1978  The application link interface in the NTT DOCOMO sp mode mail application 6100 through 6300 for Android 4.0.x and 6130 through 6700 for Android 4.1 through 4.4 writes message content to the SD card during e-mail composition, which allows attackers to obtain sensitive information via a crafted application.    4.3  Medium  2017-01-19  2014-03-20  View
30747  CVE-2014-2313  Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.    4.3  Medium  2017-01-19  2014-03-10  View

Page 993 of 17672, showing 5 records out of 88360 total, starting on record 4961, ending on 4965

Actions