NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
23258 | CVE-2015-0819 | The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
23514 | CVE-2015-1128 | The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsing-history information via vectors involving push-notification requests. | 2 | 5 | Medium | 2017-01-19 | 2015-09-11 | View | |
23770 | CVE-2015-1456 | Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/. | 2 | 4 | Medium | 2017-01-19 | 2015-02-19 | View | |
24026 | CVE-2015-1782 | The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet. | 2 | 6.8 | Medium | 2017-01-19 | 2017-01-02 | View | |
24794 | CVE-2015-2807 | Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View |
Page 16344 of 17672, showing 5 records out of 88360 total, starting on record 81716, ending on 81720