NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23264  CVE-2015-0825  Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.    4.3  Medium  2017-01-19  2016-12-21  View
24032  CVE-2015-1792  The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL value of a BIO data structure, as demonstrated by an unrecognized X.660 OID for a hash function.    Medium  2017-01-19  2016-12-30  View
24288  CVE-2015-2136  HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.    Medium  2017-01-19  2015-09-17  View
24800  CVE-2015-2813  XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358.    Medium  2017-01-19  2016-12-02  View
25312  CVE-2015-3664  QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3665 and CVE-2015-3669.    6.8  Medium  2017-01-19  2016-12-27  View

Page 16550 of 17672, showing 5 records out of 88360 total, starting on record 82746, ending on 82750

Actions