NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 22743 | CVE-2015-0254 | Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag. | 2 | 7.5 | High | 2017-01-19 | 2016-12-21 | View | |
| 88279 | CVE-2017-9917 | IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77df0000!RtlFreeHandle+0x0000000000000218. | 2 | 4.4 | Medium | 2017-07-18 | 2017-07-11 | View | |
| 22999 | CVE-2015-0525 | The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2015-09-10 | View | |
| 23255 | CVE-2015-0816 | Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 23511 | CVE-2015-1125 | The touch-events implementation in WebKit in Apple iOS before 8.3 allows remote attackers to trigger an association between a tap and an unintended web resource via a crafted web site. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-11 | View |
Page 14917 of 17672, showing 5 records out of 88360 total, starting on record 74581, ending on 74585