NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24323 | CVE-2015-2198 | Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage_url, (2) pic_url, or (3) avatar_url parameter, which are not properly handled in an error message. | 2 | 4.3 | Medium | 2017-01-19 | 2015-03-04 | View | |
24835 | CVE-2015-2855 | The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not set the secure flag for the administrator"s cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, a different vulnerability than CVE-2015-4138. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
25091 | CVE-2015-3192 | Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
25859 | CVE-2015-4415 | Multiple directory traversal vulnerabilities in func.php in Magnifica Webscripts Anima Gallery 2.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) theme or (2) lang cookie parameter to AnimaGallery/. | 2 | 5 | Medium | 2017-01-19 | 2016-06-15 | View | |
26115 | CVE-2015-4793 | Unspecified vulnerability in the Oracle Communications Convergence component in Oracle Communications Applications 2.0 and 3.0.1 allows remote attackers to affect confidentiality via unknown vectors related to Mail Proxy. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View |
Page 133 of 17672, showing 5 records out of 88360 total, starting on record 661, ending on 665