NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26396  CVE-2015-5144  Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to the (3) validate_ipv4_address or (4) validate_slug validator.    4.3  Medium  2017-01-19  2016-12-23  View
27420  CVE-2015-6523  Cross-site request forgery (CSRF) vulnerability in the Portfolio plugin before 1.05 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the instagram-portfolio page in wp-admin/options-general.php.    6.8  Medium  2017-01-19  2016-12-21  View
27676  CVE-2015-6858  HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors.    4.3  Medium  2017-01-19  2016-11-28  View
27932  CVE-2015-7254  Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.    Medium  2017-01-19  2016-12-07  View
28188  CVE-2015-7707  Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.    6.5  Medium  2017-01-19  2015-10-06  View

Page 1029 of 17672, showing 5 records out of 88360 total, starting on record 5141, ending on 5145

Actions