NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 31700 | CVE-2014-3515 | The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage. | 2 | 7.5 | High | 2017-01-19 | 2017-01-06 | View | |
| 31956 | CVE-2014-3862 | CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log. | 2 | 4.3 | Medium | 2017-01-19 | 2014-09-02 | View | |
| 32212 | CVE-2014-4194 | SQL injection vulnerability in zero_transact_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a Submit Comment action. | 2 | 7.5 | High | 2017-01-19 | 2015-09-02 | View | |
| 32468 | CVE-2014-4483 | Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font file in a PDF document. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-17 | View | |
| 32724 | CVE-2014-4819 | The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page. | 2 | 4 | Medium | 2017-01-19 | 2015-11-06 | View |
Page 15038 of 17672, showing 5 records out of 88360 total, starting on record 75186, ending on 75190