NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 29921 | CVE-2014-1236 | Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via vectors related to a "badly formed number" and a "long digit list." | 2 | 10 | High | 2017-01-19 | 2015-08-07 | View | |
| 30177 | CVE-2014-1552 | Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 30433 | CVE-2014-1895 | Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 30689 | CVE-2014-2231 | Cross-site scripting (XSS) vulnerability in the API in synetics i-doit pro before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via a property title. | 2 | 4.3 | Medium | 2017-01-19 | 2014-02-28 | View | |
| 30945 | CVE-2014-2527 | kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528. | 2 | 6.8 | Medium | 2017-01-19 | 2014-08-27 | View |
Page 15829 of 17672, showing 5 records out of 88360 total, starting on record 79141, ending on 79145