NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25645 | CVE-2015-4158 | SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2121661. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
25901 | CVE-2015-4478 | Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method. | 2 | 5 | Medium | 2017-01-19 | 2016-12-23 | View | |
26413 | CVE-2015-5174 | Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory. | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
26925 | CVE-2015-5862 | The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
27693 | CVE-2015-6920 | Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-17 | View |
Page 1640 of 17672, showing 5 records out of 88360 total, starting on record 8196, ending on 8200