NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83900  CVE-2015-8623  The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.    6.8  Medium  2017-03-29  2017-03-27  View
83899  CVE-2015-8622  Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when is configured with a relative URL, allows remote authenticated users to inject arbitrary web script or HTML via wikitext, as demonstrated by a wikilink to a page named "javascript:alert("XSS!")."    4.3  Medium  2017-03-29  2017-03-27  View
28712  CVE-2015-8620  Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privileges via a Unicode file path in an IOCTL request.    10  High  2017-01-19  2016-04-14  View
85261  CVE-2015-8619  The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).    Medium  2017-04-27  2017-04-20  View
28711  CVE-2015-8618  The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.    Medium  2017-01-19  2016-05-26  View

Page 2591 of 17672, showing 5 records out of 88360 total, starting on record 12951, ending on 12955

Actions