Skip to main content

CWE archive

CWE-254 CVEs

Programmatic archive

414 CVEs tagged with CWE-25437 Critical, 126 High, 220 Medium, 31 Low, 0 Unrated.

CVE-2015-6582

Published Sep 3, 2015

The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, w…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1300

Published Sep 3, 2015

The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1298

Published Sep 3, 2015

The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstall…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1297

Published Sep 3, 2015

The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source befor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1296

Published Sep 3, 2015

The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, wh…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0943

Published Aug 31, 2015

Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryp…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4498

Published Aug 29, 2015

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-5501

Published Aug 18, 2015

The Hostmaster (Aegir) module 6.x-2.x before 6.x-2.4 and 7.x-3.x before 7.x-3.0-beta2 for Drupal allows remote attackers to execute arbitrary PHP code via a crafted file in the di…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5759

Published Aug 17, 2015

WebKit in Apple iOS before 8.4.1 allows remote attackers to spoof clicks via a crafted web site that leverages tap events.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3756

Published Aug 16, 2015

The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitra…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-3755

Published Aug 16, 2015

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3751

Published Aug 16, 2015

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security P…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3750

Published Aug 16, 2015

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (H…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3729

Published Aug 16, 2015

Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, whic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1281

Published Jul 23, 2015

core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to byp…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2015-1278

Published Jul 23, 2015

content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstit…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2015-1274

Published Jul 23, 2015

Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by p…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2014-9196

Published Jul 20, 2015

Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which mak…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-3449

Published Jul 16, 2015

The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Tr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3728

Published Jul 3, 2015

The WiFi Connectivity feature in Apple iOS before 8.4 allows remote Wi-Fi access points to trigger an automatic association, with an arbitrary security type, by operating with a r…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3722

Published Jul 3, 2015

Application Store in Apple iOS before 8.4 does not ensure the uniqueness of bundle IDs, which allows attackers to cause a denial of service (ID collision and launch outage) via a…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2015-3715

Published Jul 3, 2015

The code-signing implementation in Apple OS X before 10.10.4 does not properly consider libraries that are external to an application bundle, which allows attackers to bypass inte…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 414 CVEsPage 15 of 17