NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
26826 | CVE-2015-5761 | CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5755. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-23 | View | |
27082 | CVE-2015-6061 | Cross-site scripting (XSS) vulnerability in Microsoft Skype for Business 2016, Lync 2010 and 2013 SP1, Lync 2010 Attendee, and Lync Room System allows remote attackers to inject arbitrary web script or HTML via an instant-message session, aka "Server Input Validation Information Disclosure Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
28106 | CVE-2015-7578 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
28362 | CVE-2015-8002 | The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 allows remote authenticated users to cause a denial of service (disk consumption) via a file upload using one byte chunks. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-10 | View | |
28874 | CVE-2015-8840 | The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or (3) webcontent/aas/aas_store.jsp, aka SAP Security Note 1945215. | 2 | 6.5 | Medium | 2017-01-19 | 2016-04-11 | View |
Page 15770 of 17672, showing 5 records out of 88360 total, starting on record 78846, ending on 78850