CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
95327 | CVE-2016-8507 | Candidate | Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user"s approval and obtain video and audio data from a device via a crafted web site. | Assigned (20161007) | None (candidate not yet proposed) | View | |
95322 | CVE-2016-8502 | Candidate | Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript. | Assigned (20161007) | None (candidate not yet proposed) | View | |
95323 | CVE-2016-8503 | Candidate | Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript. | Assigned (20161007) | None (candidate not yet proposed) | View | |
72012 | CVE-2014-4715 | Candidate | Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611. | Assigned (20140702) | None (candidate not yet proposed) | View | |
57500 | CVE-2012-4257 | Candidate | Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message. | Assigned (20120813) | None (candidate not yet proposed) | View |
Page 20899 of 20943, showing 5 records out of 104715 total, starting on record 104491, ending on 104495