NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25260 | CVE-2015-3418 | The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request. | 2 | 5 | Medium | 2017-01-19 | 2016-12-15 | View | |
| 25772 | CVE-2015-4303 | Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID CSCuv12333. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 26028 | CVE-2015-4670 | Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd. | 2 | 6.4 | Medium | 2017-01-19 | 2015-08-20 | View | |
| 26540 | CVE-2015-5356 | Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the func parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-02 | View | |
| 26796 | CVE-2015-5720 | Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxification.js. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 14714 of 17672, showing 5 records out of 88360 total, starting on record 73566, ending on 73570