NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
28653 | CVE-2015-8510 | Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted web site that is mishandled during "Add to home screen" bookmarking. | 2 | 4.3 | Medium | 2017-01-19 | 2016-01-14 | View | |
28909 | CVE-2015-8917 | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
29677 | CVE-2014-0829 | Multiple buffer overflows in IBM Rational ClearCase 7.x before 7.1.2.13, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.3 allow remote authenticated users to obtain privileged access via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-19 | 2015-05-08 | View | |
30189 | CVE-2014-1564 | Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-06 | View | |
30701 | CVE-2014-2244 | Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-07 | View |
Page 17004 of 17672, showing 5 records out of 88360 total, starting on record 85016, ending on 85020