NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35385 | CVE-2014-8267 | Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-02-02 | View | |
| 35641 | CVE-2014-8640 | The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a denial of service (uninitialized-memory read and application crash) via crafted API calls. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 35897 | CVE-2014-9119 | Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | 2 | 5 | Medium | 2017-01-19 | 2015-01-02 | View | |
| 36409 | CVE-2014-9886 | arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate input parameters, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28815575 and Qualcomm internal bug CR555030. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 37177 | CVE-2013-0909 | The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors. | 2 | 5 | Medium | 2017-01-18 | 2016-10-13 | View |
Page 2072 of 17672, showing 5 records out of 88360 total, starting on record 10356, ending on 10360