31688 |
CVE-2014-3503 |
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack. |
|
2 |
5 |
Medium |
2017-01-19 |
2014-07-11 |
View
|
31944 |
CVE-2014-3846 |
Cross-site scripting (XSS) vulnerability in Flying Cart allows remote attackers to inject arbitrary web script or HTML via the p parameter to index.php. |
|
2 |
4.3 |
Medium |
2017-01-19 |
2014-06-25 |
View
|
32200 |
CVE-2014-4166 |
Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the mp3 title field. |
|
2 |
4.3 |
Medium |
2017-01-19 |
2014-06-17 |
View
|
32456 |
CVE-2014-4469 |
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1. |
|
2 |
6.8 |
Medium |
2017-01-19 |
2016-11-28 |
View
|
32712 |
CVE-2014-4807 |
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a " |