NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26915 | CVE-2015-5851 | The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-21 | View | |
| 35875 | CVE-2014-9066 | Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065. | 2 | 4.7 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 23588 | CVE-2015-1226 | The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intended access restrictions via a crafted extension. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 27428 | CVE-2015-6535 | Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter). | 2 | 3.5 | Low | 2017-01-19 | 2016-12-21 | View | |
| 27684 | CVE-2015-6908 | The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View |
Page 3192 of 17672, showing 5 records out of 88360 total, starting on record 15956, ending on 15960