NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25519 | CVE-2015-3935 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (search_nom) field to (1) htdocs/societe/societe.php or (2) htdocs/societe/admin/societe.php. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 27055 | CVE-2015-6029 | HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 28079 | CVE-2015-7519 | agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header. | 2 | 4.3 | Medium | 2017-01-19 | 2016-01-13 | View | |
| 28335 | CVE-2015-7940 | The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack." | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 28847 | CVE-2015-8797 | Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI. | 2 | 4.3 | Medium | 2017-01-19 | 2016-02-22 | View |
Page 14820 of 17672, showing 5 records out of 88360 total, starting on record 74096, ending on 74100