NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
27595 | CVE-2015-6756 | Use-after-free vulnerability in the CPDFSDK_PageView implementation in fpdfsdk/src/fsdk_mgr.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging mishandling of a focused annotation in a PDF document. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-23 | View | |
27851 | CVE-2015-7107 | QuickLook in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted iWork file. | 2 | 6.8 | Medium | 2017-01-19 | 2015-12-11 | View | |
28107 | CVE-2015-7579 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
28363 | CVE-2015-8003 | MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-10 | View | |
29131 | CVE-2014-0220 | Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API. | 2 | 4 | Medium | 2017-01-19 | 2014-06-24 | View |
Page 15806 of 17672, showing 5 records out of 88360 total, starting on record 79026, ending on 79030