NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
30433  CVE-2014-1895  Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.    5.8  Medium  2017-01-19  2017-01-06  View
30689  CVE-2014-2231  Cross-site scripting (XSS) vulnerability in the API in synetics i-doit pro before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via a property title.    4.3  Medium  2017-01-19  2014-02-28  View
30945  CVE-2014-2527  kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528.    6.8  Medium  2017-01-19  2014-08-27  View
31201  CVE-2014-2871  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attackers to obtain sensitive information by sniffing the network.    Medium  2017-01-19  2014-04-16  View
31457  CVE-2014-3243  SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.    Medium  2017-01-19  2014-05-13  View

Page 16590 of 17672, showing 5 records out of 88360 total, starting on record 82946, ending on 82950

Actions