NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25631 | CVE-2015-4140 | Cross-site request forgery (CSRF) vulnerability in the WP Smiley plugin 1.4.1 for WordPress allows remote attackers to hijack the authentication of editors for requests that conduct cross-site scripting (XSS) attacks via the s4w-more parameter to the smilies4wp.php page to wp-admin/options-general.php. | 2 | 6.8 | Medium | 2017-01-19 | 2015-06-19 | View | |
25887 | CVE-2015-4458 | The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-21 | View | |
27423 | CVE-2015-6526 | The perf_callchain_user_64 function in arch/powerpc/perf/callchain.c in the Linux kernel before 4.0.2 on ppc64 platforms allows local users to cause a denial of service (infinite loop) via a deep 64-bit userspace backtrace. | 2 | 4.9 | Medium | 2017-01-19 | 2016-12-07 | View | |
27679 | CVE-2015-6861 | HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a user"s account. | 2 | 4.6 | Medium | 2017-01-19 | 2016-11-28 | View | |
28191 | CVE-2015-7712 | Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated users with the AT_PRIV_GRADEBOOK privilege to execute arbitrary PHP code via the (1) asc or (2) desc parameter. | 2 | 6.5 | Medium | 2017-01-19 | 2015-11-17 | View |
Page 1139 of 17672, showing 5 records out of 88360 total, starting on record 5691, ending on 5695