NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35872 | CVE-2014-9059 | lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-03 | View | |
| 36128 | CVE-2014-9425 | Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 2 | 7.5 | High | 2017-01-19 | 2016-12-06 | View | |
| 36384 | CVE-2014-9803 | arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Android before 2016-07-05 on Nexus 5X and 6P devices, mishandles execute-only pages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28557020. | 2 | 9.3 | High | 2017-01-19 | 2016-07-12 | View | |
| 36640 | CVE-2013-0289 | Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 4.3 | Medium | 2017-01-18 | 2014-06-27 | View | |
| 36896 | CVE-2013-0591 | Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0590. | 2 | 3.5 | Low | 2017-01-18 | 2013-08-27 | View |
Page 1962 of 17672, showing 5 records out of 88360 total, starting on record 9806, ending on 9810