NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35111 | CVE-2014-7817 | The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))". | 2 | 4.6 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 35367 | CVE-2014-8160 | net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 35623 | CVE-2014-8617 | Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMail before 4.3.9, 5.0.x before 5.0.8, 5.1.x before 5.1.5, and 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via the release parameter to module/releasecontrol. | 2 | 4.3 | Medium | 2017-01-19 | 2015-11-19 | View | |
| 35879 | CVE-2014-9091 | Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors. | 2 | 4.6 | Medium | 2017-01-19 | 2014-12-11 | View | |
| 36135 | CVE-2014-9432 | Multiple cross-site scripting (XSS) vulnerabilities in templates/2k11/admin/overview.inc.tpl in Serendipity before 2.0-rc2 allow remote attackers to inject arbitrary web script or HTML via a blog comment in the QUERY_STRING to serendipity/index.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-01-12 | View |
Page 3141 of 17672, showing 5 records out of 88360 total, starting on record 15701, ending on 15705