NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31189 | CVE-2014-2859 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request. | 2 | 7.5 | High | 2017-01-19 | 2014-04-16 | View | |
32469 | CVE-2014-4484 | FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .dfont file. | 2 | 7.5 | High | 2017-01-19 | 2015-11-17 | View | |
32981 | CVE-2014-5250 | Unspecified vulnerability in the AJAX autocompletion callback in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to access data via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2014-08-14 | View | |
35541 | CVE-2014-8514 | Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers. | 2 | 7.5 | High | 2017-01-19 | 2016-12-30 | View | |
36565 | CVE-2013-0209 | lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code. | 2 | 7.5 | High | 2017-01-18 | 2013-01-29 | View |
Page 16163 of 17672, showing 5 records out of 88360 total, starting on record 80811, ending on 80815