NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26404 | CVE-2015-5156 | The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets. | 2 | 6.1 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26660 | CVE-2015-5523 | The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26916 | CVE-2015-5853 | AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload data via unspecified vectors. | 2 | 3.3 | Low | 2017-01-19 | 2016-12-09 | View | |
| 27172 | CVE-2015-6164 | Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability." | 2 | 6.8 | Medium | 2017-01-19 | 2015-12-09 | View | |
| 27428 | CVE-2015-6535 | Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter). | 2 | 3.5 | Low | 2017-01-19 | 2016-12-21 | View |
Page 2196 of 17672, showing 5 records out of 88360 total, starting on record 10976, ending on 10980