NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26622 | CVE-2015-5479 | The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 26623 | CVE-2015-5481 | Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 26624 | CVE-2015-5482 | Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php. | 2 | 4 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 26625 | CVE-2015-5485 | Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-19 | View | |
| 26626 | CVE-2015-5487 | Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows remote authenticated users with the "view meta information" permission to inject arbitrary web script or HTML via unspecified vectors related to the meta access tab. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-03 | View |
Page 14644 of 17672, showing 5 records out of 88360 total, starting on record 73216, ending on 73220