NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27601  CVE-2015-6762  The CSSFontFaceSrcValue::fetch function in core/css/CSSFontFaceSrcValue.cpp in the Cascading Style Sheets (CSS) implementation in Blink, as used in Google Chrome before 46.0.2490.71, does not use the CORS cross-origin request algorithm when a font"s URL appears to be a same-origin URL, which allows remote web servers to bypass the Same Origin Policy via a redirect.    7.5  High  2017-01-19  2016-12-23  View
27857  CVE-2015-7113  The LaunchServices component in Apple iOS before 9.2 and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a malformed plist.    10  High  2017-01-19  2016-12-07  View
28113  CVE-2015-7603  Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a .. (dot dot backslash) in a RETR command.    7.8  High  2017-01-19  2015-09-30  View
28369  CVE-2015-8020  Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure.    4.3  Medium  2017-01-19  2017-01-12  View
28881  CVE-2015-8853  The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "ax80."    Medium  2017-01-19  2016-11-28  View

Page 14392 of 17672, showing 5 records out of 88360 total, starting on record 71956, ending on 71960

Actions