NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24573 | CVE-2015-2548 | Use-after-free vulnerability in the Tablet Input Band in Windows Shell in Microsoft Windows Vista SP2 and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Tablet Input Band Use After Free Vulnerability." | 2 | 9.3 | High | 2017-01-19 | 2016-12-12 | View | |
24829 | CVE-2015-2849 | SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices, when https is used, allows remote attackers to execute arbitrary SQL commands via the ppli parameter. | 2 | 7.5 | High | 2017-01-19 | 2015-07-08 | View | |
25085 | CVE-2015-3183 | The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c. | 2 | 5 | Medium | 2017-01-19 | 2016-12-23 | View | |
25341 | CVE-2015-3694 | FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3719. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
25597 | CVE-2015-4063 | Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php. | 2 | 3.5 | Low | 2017-01-19 | 2015-05-28 | View |
Page 17522 of 17672, showing 5 records out of 88360 total, starting on record 87606, ending on 87610