NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25448 | CVE-2015-3801 | The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 25960 | CVE-2015-4538 | The XML parser in EMC Atmos before 2.2.3.426 and 2.3.x before 2.3.1.0 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 7.5 | High | 2017-01-19 | 2016-12-21 | View | |
| 23657 | CVE-2015-1297 | The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request"s source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension. | 2 | 7.5 | High | 2017-01-19 | 2016-12-21 | View | |
| 23658 | CVE-2015-1298 | The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninstalled. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 24682 | CVE-2015-2661 | Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows local users to affect availability via unknown vectors related to Client. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-21 | View |
Page 3225 of 17672, showing 5 records out of 88360 total, starting on record 16121, ending on 16125