NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 31711 | CVE-2014-3530 | The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. | 2 | 7.5 | High | 2017-01-19 | 2017-01-06 | View | |
| 31967 | CVE-2014-3877 | Incomplete blacklist vulnerability in Frams" Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the addto parameter to fup. | 2 | 4.3 | Medium | 2017-01-19 | 2014-06-18 | View | |
| 32223 | CVE-2014-4207 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR. | 2 | 4 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 32479 | CVE-2014-4495 | The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which allows attackers to bypass intended access restrictions via a crafted app. | 2 | 10 | High | 2017-01-19 | 2015-11-17 | View | |
| 32735 | CVE-2014-4830 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | 2 | 4.3 | Medium | 2017-01-19 | 2014-12-30 | View |
Page 14668 of 17672, showing 5 records out of 88360 total, starting on record 73336, ending on 73340