NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
36079  CVE-2014-9367  Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to conduct cross-site scripting (XSS) attacks via a """ (single quote) in the scope parameter to do/view/TWiki/WebSearch.    4.3  Medium  2017-01-19  2015-01-02  View
36335  CVE-2014-9744  Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of ClientHello messages. NOTE: this identifier was SPLIT from CVE-2014-8628 per ADT3 due to different affected versions.    7.8  High  2017-01-19  2015-08-25  View
36591  CVE-2013-0235  The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.    6.4  Medium  2017-01-18  2013-07-08  View
36847  CVE-2013-0513  IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program, related to an "Unquoted Service Path Enumeration" vulnerability.    7.2  High  2017-01-18  2013-03-29  View
37103  CVE-2013-0833  Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to printing.    Medium  2017-01-18  2016-10-13  View

Page 14481 of 17672, showing 5 records out of 88360 total, starting on record 72401, ending on 72405

Actions