NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25400 | CVE-2015-3753 | WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource. | 2 | 5 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 25656 | CVE-2015-4174 | Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet/IP communication module with firmware before 10.34 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26168 | CVE-2015-4847 | Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via vectors related to OCI. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 27192 | CVE-2015-6246 | The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandles large tag values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 27960 | CVE-2015-7309 | The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it. | 2 | 6.5 | Medium | 2017-01-19 | 2015-09-23 | View |
Page 2030 of 17672, showing 5 records out of 88360 total, starting on record 10146, ending on 10150