NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30433 | CVE-2014-1895 | Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
30689 | CVE-2014-2231 | Cross-site scripting (XSS) vulnerability in the API in synetics i-doit pro before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via a property title. | 2 | 4.3 | Medium | 2017-01-19 | 2014-02-28 | View | |
30945 | CVE-2014-2527 | kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528. | 2 | 6.8 | Medium | 2017-01-19 | 2014-08-27 | View | |
31201 | CVE-2014-2871 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attackers to obtain sensitive information by sniffing the network. | 2 | 5 | Medium | 2017-01-19 | 2014-04-16 | View | |
31457 | CVE-2014-3243 | SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references. | 2 | 5 | Medium | 2017-01-19 | 2014-05-13 | View |
Page 16590 of 17672, showing 5 records out of 88360 total, starting on record 82946, ending on 82950