NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27285 | CVE-2015-6348 | The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page. | 2 | 4 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27286 | CVE-2015-6349 | Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27287 | CVE-2015-6350 | SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuw50843. | 2 | 6.5 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27288 | CVE-2015-6351 | Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices with software 19.1.0.61559 and 19.2.0 allow remote attackers to cause a denial of service (BGP process restart) via a crafted header in a BGP packet, aka Bug ID CSCuw65781. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27289 | CVE-2015-6352 | Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut67891. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 14778 of 17672, showing 5 records out of 88360 total, starting on record 73886, ending on 73890