NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27601 | CVE-2015-6762 | The CSSFontFaceSrcValue::fetch function in core/css/CSSFontFaceSrcValue.cpp in the Cascading Style Sheets (CSS) implementation in Blink, as used in Google Chrome before 46.0.2490.71, does not use the CORS cross-origin request algorithm when a font"s URL appears to be a same-origin URL, which allows remote web servers to bypass the Same Origin Policy via a redirect. | 2 | 7.5 | High | 2017-01-19 | 2016-12-23 | View | |
| 27857 | CVE-2015-7113 | The LaunchServices component in Apple iOS before 9.2 and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a malformed plist. | 2 | 10 | High | 2017-01-19 | 2016-12-07 | View | |
| 28113 | CVE-2015-7603 | Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a .. (dot dot backslash) in a RETR command. | 2 | 7.8 | High | 2017-01-19 | 2015-09-30 | View | |
| 28369 | CVE-2015-8020 | Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-12 | View | |
| 28881 | CVE-2015-8853 | The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "ax80." | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 14392 of 17672, showing 5 records out of 88360 total, starting on record 71956, ending on 71960