NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35824 | CVE-2014-8995 | SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie. | 2 | 5 | Medium | 2017-01-19 | 2014-11-20 | View | |
36080 | CVE-2014-9368 | Cross-site request forgery (CSRF) vulnerability in the twitterDash plugin 2.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the username_twitterDash parameter in the twitterDash.php page to wp-admin/options-general.php. | 2 | 6.8 | Medium | 2017-01-19 | 2014-12-22 | View | |
36336 | CVE-2014-9745 | The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
36592 | CVE-2013-0236 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post. | 2 | 4.3 | Medium | 2017-01-18 | 2013-07-08 | View | |
36848 | CVE-2013-0518 | IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 does not refuse to be rendered in different-origin frames, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. | 2 | 4.3 | Medium | 2017-01-18 | 2013-05-10 | View |
Page 16630 of 17672, showing 5 records out of 88360 total, starting on record 83146, ending on 83150