NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35638 | CVE-2014-8637 | Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 22839 | CVE-2015-0361 | Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during HVM guest teardown. | 2 | 7.8 | High | 2017-01-19 | 2017-01-02 | View | |
| 23607 | CVE-2015-1246 | Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 35639 | CVE-2014-8638 | The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site. | 2 | 6.8 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 23608 | CVE-2015-1247 | The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote attackers to obtain sensitive information from local files via a crafted (1) http or (2) https web site. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View |
Page 2786 of 17672, showing 5 records out of 88360 total, starting on record 13926, ending on 13930