NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 30177 | CVE-2014-1552 | Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 30433 | CVE-2014-1895 | Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 30689 | CVE-2014-2231 | Cross-site scripting (XSS) vulnerability in the API in synetics i-doit pro before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via a property title. | 2 | 4.3 | Medium | 2017-01-19 | 2014-02-28 | View | |
| 30945 | CVE-2014-2527 | kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528. | 2 | 6.8 | Medium | 2017-01-19 | 2014-08-27 | View | |
| 31201 | CVE-2014-2871 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attackers to obtain sensitive information by sniffing the network. | 2 | 5 | Medium | 2017-01-19 | 2014-04-16 | View |
Page 14706 of 17672, showing 5 records out of 88360 total, starting on record 73526, ending on 73530