Skip to main content

CWE archive

CWE-254 CVEs

Programmatic archive

414 CVEs tagged with CWE-25437 Critical, 126 High, 220 Medium, 31 Low, 0 Unrated.

CVE-2015-3996

Published Oct 27, 2015

The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework before 2.5.3, as used in the ownCloud iOS Library, disables v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5943

Published Oct 23, 2015

SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain windows, which allows attackers to bypass intended access restrictions via a cr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6999

Published Oct 23, 2015

The OCSP client in Apple iOS before 9.1 does not check for certificate expiry, which allows remote attackers to spoof a valid certificate by leveraging access to a revoked certifi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6997

Published Oct 23, 2015

The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7863

Published Oct 19, 2015

The default configuration of Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 enables a remote Notify capability wit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6762

Published Oct 15, 2015

The CSSFontFaceSrcValue::fetch function in core/css/CSSFontFaceSrcValue.cpp in the Cascading Style Sheets (CSS) implementation in Blink, as used in Google Chrome before 46.0.2490.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5900

Published Oct 9, 2015

The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a craft…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5833

Published Oct 9, 2015

The Login Window component in Apple OS X before 10.11 does not ensure that the screen is locked at the intended time, which allows physically proximate attackers to obtain access…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4520

Published Sep 24, 2015

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4516

Published Sep 24, 2015

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute ar…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4508

Published Sep 24, 2015

Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4502

Published Sep 24, 2015

js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a craf…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4476

Published Sep 24, 2015

Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstan…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5905

Published Sep 18, 2015

Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5904

Published Sep 18, 2015

Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5857

Published Sep 18, 2015

Mail in Apple iOS before 9 allows remote attackers to use an address-book contact as a spoofed e-mail sender address via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5856

Published Sep 18, 2015

The Application Store component in Apple iOS before 9 allows remote attackers to cause a denial of service to an enterprise-signed app via a crafted ITMS URL.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5850

Published Sep 18, 2015

AppleKeyStore in Apple iOS before 9 allows physically proximate attackers to reset the count of incorrect passcode attempts via a device backup.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-6583

Published Sep 3, 2015

Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 414 CVEsPage 14 of 17