NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23206 | CVE-2015-0752 | Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-04 | View | |
| 23462 | CVE-2015-1076 | WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 23718 | CVE-2015-1373 | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter in a search request, (2) username in a login request, which is not properly handled when logging the event, or (3) page title in an insert action. | 2 | 4.3 | Medium | 2017-01-19 | 2015-01-27 | View | |
| 24742 | CVE-2015-2741 | Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-27 | View | |
| 25254 | CVE-2015-3411 | PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename .xml attack that bypasses an intended configuration in which client users may read only .xml files. | 2 | 6.4 | Medium | 2017-01-19 | 2016-11-29 | View |
Page 14507 of 17672, showing 5 records out of 88360 total, starting on record 72531, ending on 72535