NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35896 | CVE-2014-9117 | MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPTCHA answer for a public_key parameter value, as demonstrated by E4652 for the public_key value 0. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 36152 | CVE-2014-9449 | Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash) via a long IKEY INFO tag value in an AVI file. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 36408 | CVE-2014-9885 | Format string vulnerability in drivers/thermal/qpnp-adc-tm.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices allows attackers to gain privileges via a crafted application that provides format string specifiers in a name, aka Android internal bug 28769959 and Qualcomm internal bug CR562261. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 36664 | CVE-2013-0317 | Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete field. | 2 | 4.3 | Medium | 2017-01-18 | 2013-04-04 | View | |
| 37688 | CVE-2013-1496 | Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/IO, a different vulnerability than CVE-2013-1498. | 2 | 4.9 | Medium | 2017-01-18 | 2016-11-09 | View |
Page 2035 of 17672, showing 5 records out of 88360 total, starting on record 10171, ending on 10175