NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25306 | CVE-2015-3658 | The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, which makes it easier for remote attackers to bypass CSRF protection mechanisms via a crafted web site. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-27 | View | |
| 25562 | CVE-2015-3994 | The grant.xsfunc application in testApps/grantAccess/ in the XS Engine in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to spoof log entries via a crafted request, aka SAP Security Note 2109818. | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 25818 | CVE-2015-4360 | Cross-site request forgery (CSRF) vulnerability in the Registration codes module before 6.x-1.6, 6.x-2.x before 6.x-2.8, and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete role-rules via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2015-06-30 | View | |
| 26074 | CVE-2015-4752 | Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to Server : I_S. | 2 | 4 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 26842 | CVE-2015-5778 | CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-5777. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-23 | View |
Page 16345 of 17672, showing 5 records out of 88360 total, starting on record 81721, ending on 81725