NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25118 | CVE-2015-3227 | The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View | |
25374 | CVE-2015-3727 | WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site"s database via a crafted web site. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-27 | View | |
25630 | CVE-2015-4139 | Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the s4w-more parameter to wp-admin/options-general.php. | 2 | 3.5 | Low | 2017-01-19 | 2015-06-19 | View | |
25886 | CVE-2015-4456 | ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user"s certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate. | 2 | 2.6 | Low | 2017-01-19 | 2016-12-23 | View | |
26142 | CVE-2015-4821 | Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web. | 2 | 9.3 | High | 2017-01-19 | 2016-12-23 | View |
Page 1833 of 17672, showing 5 records out of 88360 total, starting on record 9161, ending on 9165