NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 32080 | CVE-2014-4020 | The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | 2 | 4.3 | Medium | 2017-01-19 | 2014-06-19 | View | |
| 32336 | CVE-2014-4331 | Cross-site scripting (XSS) vulnerability in admin/viewer.php in OctavoCMS allows remote attackers to inject arbitrary web script or HTML via the src parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-28 | View | |
| 32592 | CVE-2014-4634 | Unquoted Windows search path vulnerability in EMC Replication Manager through 5.5.2 and AppSync before 2.1.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. | 2 | 4.6 | Medium | 2017-01-19 | 2015-03-24 | View | |
| 32848 | CVE-2014-5022 | Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-22 | View | |
| 33104 | CVE-2014-5427 | Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request. | 2 | 5 | Medium | 2017-01-19 | 2015-03-30 | View |
Page 2883 of 17672, showing 5 records out of 88360 total, starting on record 14411, ending on 14415