NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
34985  CVE-2014-7663  The Right to the Nitty Gritty (aka com.wGoNittyGritty) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    5.4  Medium  2017-01-19  2014-11-14  View
35241  CVE-2014-7987  Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.    4.3  Medium  2017-01-19  2014-11-03  View
36009  CVE-2014-9273  lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.    4.6  Medium  2017-01-19  2016-11-28  View
36777  CVE-2013-0434  Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to the public declaration of the loadPropertyFile method in the JAXP FuncSystemProperty class, which allows remote attackers to obtain sensitive information.    Medium  2017-01-18  2014-10-04  View
37289  CVE-2013-1023  WebKit, as used in Apple Safari before 6.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2013-1009.    6.8  Medium  2017-01-18  2013-06-05  View

Page 14613 of 17672, showing 5 records out of 88360 total, starting on record 73061, ending on 73065

Actions