NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
27896 | CVE-2015-7211 | Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
28664 | CVE-2015-8537 | app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed. | 2 | 5 | Medium | 2017-01-19 | 2016-04-20 | View | |
28920 | CVE-2015-8928 | The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
29944 | CVE-2014-1263 | curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate. | 2 | 4.3 | Medium | 2017-01-19 | 2014-05-05 | View | |
30456 | CVE-2014-1930 | Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation. | 2 | 4.3 | Medium | 2017-01-19 | 2014-02-21 | View |
Page 17412 of 17672, showing 5 records out of 88360 total, starting on record 87056, ending on 87060