NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25645  CVE-2015-4158  SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2121661.    Medium  2017-01-19  2016-11-28  View
25901  CVE-2015-4478  Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.    Medium  2017-01-19  2016-12-23  View
26413  CVE-2015-5174  Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.    Medium  2017-01-19  2016-12-05  View
26925  CVE-2015-5862  The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.    4.3  Medium  2017-01-19  2016-12-21  View
27693  CVE-2015-6920  Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.    4.3  Medium  2017-01-19  2015-09-17  View

Page 1640 of 17672, showing 5 records out of 88360 total, starting on record 8196, ending on 8200

Actions