NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23629  CVE-2015-1268  bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value"s DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code, as demonstrated by use of a data: URL.    Medium  2017-01-19  2016-12-30  View
24397  CVE-2015-2338  TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2339.    6.1  Medium  2017-01-19  2016-12-30  View
24909  CVE-2015-2960  Cross-site scripting (XSS) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-19  2016-12-30  View
40525  CVE-2013-5094  Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter.    4.3  Medium  2017-01-18  2016-12-30  View
23630  CVE-2015-1269  The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not entirely lowercase.    4.3  Medium  2017-01-19  2016-12-30  View

Page 14715 of 17672, showing 5 records out of 88360 total, starting on record 73571, ending on 73575

Actions