NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25307 | CVE-2015-3659 | The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-27 | View | |
| 25563 | CVE-2015-3995 | SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary files via an IMPORT FROM SQL statement, aka SAP Security Note 2109565. | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 25819 | CVE-2015-4361 | Cross-site request forgery (CSRF) vulnerability in the Registration codes module before 6.x-1.6 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete registration codes via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2015-06-30 | View | |
| 26075 | CVE-2015-4753 | Unspecified vulnerability in the RDBMS Support Tools component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality via unknown vectors. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-21 | View | |
| 26331 | CVE-2015-5061 | Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary web script or HTML via the organizationName parameter to VendorDef.do. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-07 | View |
Page 15193 of 17672, showing 5 records out of 88360 total, starting on record 75961, ending on 75965