NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
23264 | CVE-2015-0825 | Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
24032 | CVE-2015-1792 | The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL value of a BIO data structure, as demonstrated by an unrecognized X.660 OID for a hash function. | 2 | 5 | Medium | 2017-01-19 | 2016-12-30 | View | |
24288 | CVE-2015-2136 | HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2015-09-17 | View | |
24800 | CVE-2015-2813 | XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358. | 2 | 5 | Medium | 2017-01-19 | 2016-12-02 | View | |
25312 | CVE-2015-3664 | QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3665 and CVE-2015-3669. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-27 | View |
Page 16550 of 17672, showing 5 records out of 88360 total, starting on record 82746, ending on 82750