NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26411 | CVE-2015-5166 | Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice. | 2 | 7.2 | High | 2017-01-19 | 2016-12-21 | View | |
| 26412 | CVE-2015-5167 | The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API. | 2 | 4 | Medium | 2017-01-19 | 2016-04-13 | View | |
| 26413 | CVE-2015-5174 | Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory. | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 86767 | CVE-2015-5175 | Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service. | 2 | 5 | Medium | 2017-06-18 | 2017-06-15 | View | |
| 26414 | CVE-2015-5176 | The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource. | 2 | 5.8 | Medium | 2017-01-19 | 2015-08-11 | View |
Page 14599 of 17672, showing 5 records out of 88360 total, starting on record 72991, ending on 72995