NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26446  CVE-2015-5235  IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.    4.3  Medium  2017-01-19  2016-12-07  View
26447  CVE-2015-5240  Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.    3.5  Low  2017-01-19  2016-06-24  View
86337  CVE-2015-5241  After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache jUDDI 3.1.2, 3.1.3, 3.1.4, and 3.1.5 when utilizing the portlets based user interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or 'uddi-console'. User session data, credentials, and auth tokens are cleared before the redirect.    5.8  Medium  2017-06-04  2017-05-31  View
26448  CVE-2015-5242  OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).    Medium  2017-01-19  2015-11-27  View
26449  CVE-2015-5245  CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.    4.3  Medium  2017-01-19  2015-12-04  View

Page 14607 of 17672, showing 5 records out of 88360 total, starting on record 73031, ending on 73035

Actions