NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 30927 | CVE-2014-2509 | Session fixation vulnerability in the Report Advisor (RA) component in EMC Network Configuration Manager (NCM) before 9.3 allows remote attackers to hijack web sessions via a session cookie. | 2 | 5.4 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 31183 | CVE-2014-2853 | Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-10 | View | |
| 31439 | CVE-2014-3197 | The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 31695 | CVE-2014-3510 | The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote DTLS servers to cause a denial of service (NULL pointer dereference and client application crash) via a crafted handshake message in conjunction with a (1) anonymous DH or (2) anonymous ECDH ciphersuite. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 31951 | CVE-2014-3854 | Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter. | 2 | 6.8 | Medium | 2017-01-19 | 2014-08-07 | View |
Page 14379 of 17672, showing 5 records out of 88360 total, starting on record 71891, ending on 71895