NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25405 | CVE-2015-3758 | UIKit WebView in Apple iOS before 8.4.1 allows attackers to bypass an intended user-confirmation requirement and initiate arbitrary FaceTime calls via an app that provides a crafted URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 25917 | CVE-2015-4494 | Mozilla Firefox OS before 2.2 does not require the wifi-manage privilege for reading a Wi-Fi system message, which allows attackers to obtain potentially sensitive information via a crafted app. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-10 | View | |
| 26429 | CVE-2015-5208 | Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-30 | View | |
| 27453 | CVE-2015-6582 | The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted web site. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 27709 | CVE-2015-6944 | Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp. | 2 | 6.8 | Medium | 2017-01-19 | 2015-09-16 | View |
Page 2214 of 17672, showing 5 records out of 88360 total, starting on record 11066, ending on 11070