NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25072 | CVE-2015-3158 | The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow. | 2 | 4 | Medium | 2017-01-19 | 2015-08-27 | View | |
| 25328 | CVE-2015-3681 | Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015-3682. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 25584 | CVE-2015-4033 | Samsung SBeam allows remote attackers to read arbitrary images by leveraging an NFC connection to access the HTTP server on port 15000. | 2 | 3.3 | Low | 2017-01-19 | 2016-12-05 | View | |
| 25840 | CVE-2015-4382 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) create, (2) delete, or (3) alter invoices via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2015-06-26 | View | |
| 26096 | CVE-2015-4774 | Unspecified vulnerability in the Data Store component in Oracle Berkeley DB 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, and 12.1.6.0.35 allows local users to affect integrity and availability via unknown vectors, a different vulnerability than CVE-2015-4779 and CVE-2015-4788. | 2 | 3.3 | Low | 2017-01-19 | 2015-07-20 | View |
Page 14996 of 17672, showing 5 records out of 88360 total, starting on record 74976, ending on 74980