NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26535 | CVE-2015-5351 | The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 26536 | CVE-2015-5352 | The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 26537 | CVE-2015-5353 | Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tab parameter to admin/. | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View | |
| 26538 | CVE-2015-5354 | Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26539 | CVE-2015-5355 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post-content or (2) post-title parameter to admin/edit.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-02 | View |
Page 14625 of 17672, showing 5 records out of 88360 total, starting on record 73121, ending on 73125