32542 |
CVE-2014-4576 |
Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.0.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl parameter. |
|
2 |
4.3 |
Medium |
2017-01-19 |
2014-07-11 |
View
|
32798 |
CVE-2014-4905 |
The Clean Internet Browser (aka com.cleantab.browsesecure) application 1.36 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
|
2 |
5.4 |
Medium |
2017-01-19 |
2014-11-14 |
View
|
33054 |
CVE-2014-5355 |
MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a " |