NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26915  CVE-2015-5851  The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.    2.1  Low  2017-01-19  2016-12-21  View
35875  CVE-2014-9066  Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.    4.7  Medium  2017-01-19  2016-12-21  View
23588  CVE-2015-1226  The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intended access restrictions via a crafted extension.    Medium  2017-01-19  2016-12-21  View
27428  CVE-2015-6535  Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).    3.5  Low  2017-01-19  2016-12-21  View
27684  CVE-2015-6908  The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.    Medium  2017-01-19  2016-12-21  View

Page 3192 of 17672, showing 5 records out of 88360 total, starting on record 15956, ending on 15960

Actions