NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 31443 | CVE-2014-3201 | core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site that interferes with the scrollbar. | 2 | 5 | Medium | 2017-01-19 | 2014-10-10 | View | |
| 31699 | CVE-2014-3514 | activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls. | 2 | 7.5 | High | 2017-01-19 | 2017-01-06 | View | |
| 31955 | CVE-2014-3861 | Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element. | 2 | 4.3 | Medium | 2017-01-19 | 2014-09-02 | View | |
| 32211 | CVE-2014-4193 | The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by requesting long nonces from a server, a different issue than CVE-2007-6755. | 2 | 5 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 32467 | CVE-2014-4481 | Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-17 | View |
Page 14434 of 17672, showing 5 records out of 88360 total, starting on record 72166, ending on 72170