| 32030 |
CVE-2014-3952 |
FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize the buffer between the header and data of a control message, which allows local users to obtain sensitive information from kernel memory via unspecified vectors. |
|
2 |
4.9 |
Medium |
2017-01-19 |
2014-11-18 |
View
|
| 32286 |
CVE-2014-4270 |
Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to User Interface, a different vulnerability than CVE-2014-4269. |
|
2 |
4 |
Medium |
2017-01-19 |
2017-01-06 |
View
|
| 32542 |
CVE-2014-4576 |
Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.0.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl parameter. |
|
2 |
4.3 |
Medium |
2017-01-19 |
2014-07-11 |
View
|
| 32798 |
CVE-2014-4905 |
The Clean Internet Browser (aka com.cleantab.browsesecure) application 1.36 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
|
2 |
5.4 |
Medium |
2017-01-19 |
2014-11-14 |
View
|
| 33054 |
CVE-2014-5355 |
MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a " |