NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
28187 | CVE-2015-7706 | Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password. | 2 | 4.3 | Medium | 2017-01-19 | 2016-01-13 | View | |
28443 | CVE-2015-8124 | Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
30235 | CVE-2014-1626 | XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file. | 2 | 5 | Medium | 2017-01-19 | 2014-01-27 | View | |
30491 | CVE-2014-1978 | The application link interface in the NTT DOCOMO sp mode mail application 6100 through 6300 for Android 4.0.x and 6130 through 6700 for Android 4.1 through 4.4 writes message content to the SD card during e-mail composition, which allows attackers to obtain sensitive information via a crafted application. | 2 | 4.3 | Medium | 2017-01-19 | 2014-03-20 | View | |
30747 | CVE-2014-2313 | Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2014-03-10 | View |
Page 993 of 17672, showing 5 records out of 88360 total, starting on record 4961, ending on 4965