NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25448  CVE-2015-3801  The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.    Medium  2017-01-19  2016-12-21  View
25960  CVE-2015-4538  The XML parser in EMC Atmos before 2.2.3.426 and 2.3.x before 2.3.1.0 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.    7.5  High  2017-01-19  2016-12-21  View
23657  CVE-2015-1297  The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request"s source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension.    7.5  High  2017-01-19  2016-12-21  View
23658  CVE-2015-1298  The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninstalled.    4.3  Medium  2017-01-19  2016-12-21  View
24682  CVE-2015-2661  Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows local users to affect availability via unknown vectors related to Client.    2.1  Low  2017-01-19  2016-12-21  View

Page 3225 of 17672, showing 5 records out of 88360 total, starting on record 16121, ending on 16125

Actions