NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30194  CVE-2014-1569  The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data-smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_QuickDERDecodeItem function"s improper handling of an arbitrary-length encoding of 0x00.    7.5  High  2017-01-19  2016-10-03  View
32754  CVE-2014-4852  SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-19  2014-07-10  View
35570  CVE-2014-8545  libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted PNG data.    7.5  High  2017-01-19  2016-12-02  View
35826  CVE-2014-8997  Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/uploads/images/.    7.5  High  2017-01-19  2014-11-20  View
40946  CVE-2013-5697  SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.    7.5  High  2017-01-18  2013-10-11  View

Page 15575 of 17672, showing 5 records out of 88360 total, starting on record 77871, ending on 77875

Actions