| 32758 |
CVE-2014-4856 |
Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a ratings shortcode and a unique ID. NOTE: some of these details are obtained from third party information. |
|
2 |
4.3 |
Medium |
2017-01-19 |
2014-07-10 |
View
|
| 33014 |
CVE-2014-5313 |
Cross-site scripting (XSS) vulnerability in the management page in Six Apart Movable Type before 5.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. |
|
2 |
3.5 |
Low |
2017-01-19 |
2014-09-10 |
View
|
| 33526 |
CVE-2014-5902 |
The UA Cinemas - Mobile ticketing (aka com.mtel.uacinemaapps) application 2.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
|
2 |
5.4 |
Medium |
2017-01-19 |
2014-09-22 |
View
|
| 33782 |
CVE-2014-6229 |
The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses " |