NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
26624 | CVE-2015-5482 | Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php. | 2 | 4 | Medium | 2017-01-19 | 2016-12-21 | View | |
26880 | CVE-2015-5816 | WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-21 | View | |
27136 | CVE-2015-6125 | Use-after-free vulnerability in the DNS server in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Use After Free Vulnerability." | 2 | 9.3 | High | 2017-01-19 | 2015-12-09 | View | |
27392 | CVE-2015-6484 | 3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request. | 2 | 5 | Medium | 2017-01-19 | 2015-10-26 | View | |
27648 | CVE-2015-6826 | The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via crafted (1) RV30 or (2) RV40 RealVideo data. | 2 | 7.5 | High | 2017-01-19 | 2016-12-21 | View |
Page 389 of 17672, showing 5 records out of 88360 total, starting on record 1941, ending on 1945