NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
44368  CVE-2012-2645  The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.    4.3  Medium  2017-01-19  2012-07-17  View
47091  CVE-2012-6152  The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application crash) via crafted byte sequences.    Medium  2017-01-19  2014-03-16  View
40381  CVE-2013-4873  The Yahoo! Tumblr app before 3.4.1 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.    Medium  2017-01-18  2014-01-30  View
54552  CVE-2007-2385  The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."    Medium  2017-01-07  2008-11-13  View
37585  CVE-2013-1348  The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.    7.5  High  2017-01-18  2014-06-03  View

Page 15103 of 17672, showing 5 records out of 88360 total, starting on record 75511, ending on 75515

Actions