NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
26613 | CVE-2015-5461 | Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. | 2 | 6.4 | Medium | 2017-01-19 | 2016-12-07 | View | |
26869 | CVE-2015-5805 | WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-21 | View | |
27381 | CVE-2015-6470 | Resource Data Management Data Manager before 2.2 allows remote authenticated users to modify arbitrary passwords via unspecified vectors. | 2 | 5.5 | Medium | 2017-01-19 | 2015-09-28 | View | |
27893 | CVE-2015-7207 | Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
28661 | CVE-2015-8524 | Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View |
Page 17301 of 17672, showing 5 records out of 88360 total, starting on record 86501, ending on 86505