CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91407 | CVE-2016-4588 | Candidate | WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | Assigned (20160511) | None (candidate not yet proposed) | View | |
91405 | CVE-2016-4586 | Candidate | WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | Assigned (20160511) | None (candidate not yet proposed) | View | |
84381 | CVE-2015-7104 | Candidate | WebKit in Apple Safari before 9.0.2 and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | Assigned (20150916) | None (candidate not yet proposed) | View | |
81030 | CVE-2015-3753 | Candidate | WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource. | Assigned (20150507) | None (candidate not yet proposed) | View | |
81027 | CVE-2015-3750 | Candidate | WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream. | Assigned (20150507) | None (candidate not yet proposed) | View |
Page 352 of 20943, showing 5 records out of 104715 total, starting on record 1756, ending on 1760