NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
23017 | CVE-2015-0544 | EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value. | 2 | 9.3 | High | 2017-01-19 | 2016-12-27 | View | |
23273 | CVE-2015-0834 | The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
23529 | CVE-2015-1143 | LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted localized string, related to a "type confusion" issue. | 2 | 7.2 | High | 2017-01-19 | 2015-09-17 | View | |
23785 | CVE-2015-1474 | Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 allow attackers to gain privileges or cause a denial of service (memory corruption) via vectors that trigger a large number of (1) file descriptors or (2) integer values. | 2 | 10 | High | 2017-01-19 | 2016-08-25 | View | |
24041 | CVE-2015-1804 | The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via a crafted BDF font file. | 2 | 8.5 | High | 2017-01-19 | 2016-12-30 | View |
Page 16309 of 17672, showing 5 records out of 88360 total, starting on record 81541, ending on 81545