NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25977  CVE-2015-4586  Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h.HOL allows remote attackers to hijack the authentication of administrators for requests that create a user account via an add_user action in a request to password.cmd.    6.8  Medium  2017-01-19  2016-12-07  View
25978  CVE-2015-4587  Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to inject arbitrary web script or HTML via the "Custom application" field in the "port triggering" menu.    4.3  Medium  2017-01-19  2016-12-07  View
25979  CVE-2015-4588  Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.    6.8  Medium  2017-01-19  2016-12-27  View
25980  CVE-2015-4590  The extractFrom function in Internals/QuotedString.cpp in Arduino JSON before 4.5 allows remote attackers to cause a denial of service (crash) via a JSON string with a (backslash) followed by a terminator, as demonstrated by "\", which triggers a buffer overflow and over-read.    Medium  2017-01-19  2015-06-23  View
25981  CVE-2015-4591  eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter.    4.3  Medium  2017-01-19  2017-01-10  View

Page 14511 of 17672, showing 5 records out of 88360 total, starting on record 72551, ending on 72555

Actions