NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
26635 | CVE-2015-5496 | The pass2pdf module for Drupal does not restrict access to generated PDF files, which allows remote attackers to obtain user passwords via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
26891 | CVE-2015-5827 | WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) custom event, (2) message event, or (3) pop state event. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
27147 | CVE-2015-6138 | Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Internet Explorer XSS Filter Bypass Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2015-12-09 | View | |
27403 | CVE-2015-6501 | Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-17 | View | |
27659 | CVE-2015-6837 | The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consider the possibility of a NULL valuePop return value before proceeding with a free operation during initial error checking, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted XML document, a different vulnerability than CVE-2015-6838. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View |
Page 689 of 17672, showing 5 records out of 88360 total, starting on record 3441, ending on 3445