NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 44368 | CVE-2012-2645 | The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. | 2 | 4.3 | Medium | 2017-01-19 | 2012-07-17 | View | |
| 47091 | CVE-2012-6152 | The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application crash) via crafted byte sequences. | 2 | 5 | Medium | 2017-01-19 | 2014-03-16 | View | |
| 40381 | CVE-2013-4873 | The Yahoo! Tumblr app before 3.4.1 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network. | 2 | 5 | Medium | 2017-01-18 | 2014-01-30 | View | |
| 54552 | CVE-2007-2385 | The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking." | 2 | 5 | Medium | 2017-01-07 | 2008-11-13 | View | |
| 37585 | CVE-2013-1348 | The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397. | 2 | 7.5 | High | 2017-01-18 | 2014-06-03 | View |
Page 15103 of 17672, showing 5 records out of 88360 total, starting on record 75511, ending on 75515