NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
26644 | CVE-2015-5505 | The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
26900 | CVE-2015-5836 | Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-09 | View | |
27156 | CVE-2015-6147 | Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6149. | 2 | 9.3 | High | 2017-01-19 | 2016-12-07 | View | |
27412 | CVE-2015-6514 | Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Enterprise 6.2.x before 6.2.4 and Splunk Light 6.2.x before 6.2.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-19 | View | |
27668 | CVE-2015-6850 | EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allows local users to gain privileges by leveraging a login session. | 2 | 7.2 | High | 2017-01-19 | 2016-12-07 | View |
Page 1397 of 17672, showing 5 records out of 88360 total, starting on record 6981, ending on 6985