NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
29662  CVE-2014-0813  Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentication of arbitrary users for requests that modify settings.    6.8  Medium  2017-01-19  2014-02-21  View
29918  CVE-2014-1233  The paratrooper-pingdom gem 1.0.0 for Ruby allows local users to obtain the App-Key, username, and password values by listing the curl process.    2.1  Low  2017-01-19  2014-01-10  View
30174  CVE-2014-1549  The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not properly allocate Web Audio buffer memory, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via crafted audio content that is improperly handled during playback buffering.    9.3  High  2017-01-19  2017-01-06  View
30430  CVE-2014-1892  Xen 3.3 through 4.1, when XSM is enabled, allows local users to cause a denial of service via vectors related to a "large memory allocation," a different vulnerability than CVE-2014-1891, CVE-2014-1893, and CVE-2014-1894.    5.2  Medium  2017-01-19  2017-01-06  View
30686  CVE-2014-2226  Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.    2.6  Low  2017-01-19  2016-10-14  View

Page 15050 of 17672, showing 5 records out of 88360 total, starting on record 75246, ending on 75250

Actions