NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
31766  CVE-2014-3596  The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.    5.8  Medium  2017-01-19  2017-01-06  View
32022  CVE-2014-3943  Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allow remote authenticated editors to inject arbitrary web script or HTML via unknown parameters.    3.5  Low  2017-01-19  2015-09-02  View
32278  CVE-2014-4262  Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.    9.3  High  2017-01-19  2017-01-06  View
32534  CVE-2014-4568  Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.    4.3  Medium  2017-01-19  2014-07-10  View
32790  CVE-2014-4896  The Parque Imperial (aka com.a792139893520606f84b2188a.a23428594a) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    5.4  Medium  2017-01-19  2014-11-14  View

Page 1352 of 17672, showing 5 records out of 88360 total, starting on record 6756, ending on 6760

Actions