NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35567 | CVE-2014-8542 | libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View | |
35823 | CVE-2014-8994 | The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*). | 2 | 3.6 | Low | 2017-01-19 | 2015-03-04 | View | |
36079 | CVE-2014-9367 | Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to conduct cross-site scripting (XSS) attacks via a """ (single quote) in the scope parameter to do/view/TWiki/WebSearch. | 2 | 4.3 | Medium | 2017-01-19 | 2015-01-02 | View | |
36335 | CVE-2014-9744 | Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of ClientHello messages. NOTE: this identifier was SPLIT from CVE-2014-8628 per ADT3 due to different affected versions. | 2 | 7.8 | High | 2017-01-19 | 2015-08-25 | View | |
36591 | CVE-2013-0235 | The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue. | 2 | 6.4 | Medium | 2017-01-18 | 2013-07-08 | View |
Page 16684 of 17672, showing 5 records out of 88360 total, starting on record 83416, ending on 83420