NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30943 | CVE-2014-2525 | Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file. | 2 | 6.8 | Medium | 2017-01-19 | 2016-08-05 | View | |
31199 | CVE-2014-2869 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as demonstrated by pathname, SQL server, e-mail address, and IP address information. | 2 | 5 | Medium | 2017-01-19 | 2014-04-16 | View | |
31455 | CVE-2014-3227 | dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature, but is supported in environments with noncompliant patch programs, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this vulnerability exists because of reliance on unrealistic constraints on the behavior of an external program. | 2 | 6.4 | Medium | 2017-01-19 | 2014-06-24 | View | |
31967 | CVE-2014-3877 | Incomplete blacklist vulnerability in Frams" Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the addto parameter to fup. | 2 | 4.3 | Medium | 2017-01-19 | 2014-06-18 | View | |
32223 | CVE-2014-4207 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR. | 2 | 4 | Medium | 2017-01-19 | 2017-01-06 | View |
Page 16517 of 17672, showing 5 records out of 88360 total, starting on record 82581, ending on 82585