NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28361 | CVE-2015-8001 | The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk that exceeds the file size. | 2 | 3.5 | Low | 2017-01-19 | 2015-11-10 | View | |
| 28362 | CVE-2015-8002 | The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 allows remote authenticated users to cause a denial of service (disk consumption) via a file upload using one byte chunks. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-10 | View | |
| 28363 | CVE-2015-8003 | MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-10 | View | |
| 28364 | CVE-2015-8004 | MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not properly restrict access to revisions, which allows remote authenticated users with the viewsuppressed user right to remove revision suppressions via a crafted revisiondelete action, which returns a valid a change form. | 2 | 4 | Medium | 2017-01-19 | 2015-11-10 | View | |
| 28365 | CVE-2015-8005 | MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file. | 2 | 5 | Medium | 2017-01-19 | 2015-11-10 | View |
Page 15003 of 17672, showing 5 records out of 88360 total, starting on record 75011, ending on 75015