NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
27691 | CVE-2015-6915 | SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the "user" cookie to plugins/feedback/pages/feedback.php. | 2 | 7.5 | High | 2017-01-19 | 2015-09-14 | View | |
27947 | CVE-2015-7289 | Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password derived from a serial number, which makes it easier for remote attackers to obtain access via the web management interface, SSH, TELNET, or SNMP. | 2 | 9.3 | High | 2017-01-19 | 2015-11-23 | View | |
28459 | CVE-2015-8154 | The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4 allows remote attackers to execute arbitrary code via a crafted HTML document, related to "RWX Permissions." | 2 | 9.3 | High | 2017-01-19 | 2016-12-02 | View | |
29227 | CVE-2014-0328 | The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response. | 2 | 9.3 | High | 2017-01-19 | 2014-08-15 | View | |
31275 | CVE-2014-2988 | EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via crafted callback values to the call_user_func PHP function, as demonstrated using the newsettings[system] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2987. | 2 | 8.5 | High | 2017-01-19 | 2015-10-22 | View |
Page 1502 of 17672, showing 5 records out of 88360 total, starting on record 7506, ending on 7510