NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 24563 | CVE-2015-2532 | Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 24819 | CVE-2015-2839 | The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 25331 | CVE-2015-3684 | The HTTPAuthentication implementation in CFNetwork in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted credentials in a URL. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 25587 | CVE-2015-4037 | The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program. | 2 | 1.9 | Low | 2017-01-19 | 2016-12-23 | View | |
| 25843 | CVE-2015-4385 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Imagefield Info module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "Administer image styles" permission to inject arbitrary web script or HTML via unspecified vectors. | 2 | 2.1 | Low | 2017-01-19 | 2015-06-26 | View |
Page 14715 of 17672, showing 5 records out of 88360 total, starting on record 73571, ending on 73575