NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25248 | CVE-2015-3395 | The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 25247 | CVE-2015-3393 | Open redirect vulnerability in the Commerce WeDeal module before 7.x-1.3 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 25246 | CVE-2015-3392 | Cross-site scripting (XSS) vulnerability in the Ajax Timeline module before 7.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-05 | View | |
| 25245 | CVE-2015-3391 | The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and obtaining sensitive node titles by reading a 403 Not Found page. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 25244 | CVE-2015-3390 | Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher module for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-05 | View |
Page 3314 of 17672, showing 5 records out of 88360 total, starting on record 16566, ending on 16570