NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25296 | CVE-2015-3630 | Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image. | 2 | 7.2 | High | 2017-01-19 | 2017-01-02 | View | |
| 25552 | CVE-2015-3980 | SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View | |
| 25808 | CVE-2015-4350 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Spider Catalog module for Drupal allow remote attackers to hijack the authentication of administrators for requests that delete (1) products, (2) ratings, or (3) categories via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-06-09 | View | |
| 26064 | CVE-2015-4742 | Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.2.4.0, 12.1.2.0.0, and 12.1.3.0.0 allows remote attackers to affect availability via vectors related to ADF Faces. | 2 | 5 | Medium | 2017-01-19 | 2015-07-20 | View | |
| 26320 | CVE-2015-5038 | IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a denial of service (CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | 2 | 7.8 | High | 2017-01-19 | 2016-08-04 | View |
Page 14442 of 17672, showing 5 records out of 88360 total, starting on record 72206, ending on 72210