NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25064 | CVE-2015-3144 | The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80." | 2 | 9 | High | 2017-01-19 | 2016-12-21 | View | |
25320 | CVE-2015-3673 | Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility. | 2 | 7.2 | High | 2017-01-19 | 2016-12-21 | View | |
25576 | CVE-2015-4022 | Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. | 2 | 7.5 | High | 2017-01-19 | 2016-12-30 | View | |
25832 | CVE-2015-4374 | Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a component name in the recipient (To) address of an email. | 2 | 3.5 | Low | 2017-01-19 | 2015-06-26 | View | |
26088 | CVE-2015-4766 | Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows local users to affect availability via unknown vectors related to Server : Security : Firewall. | 2 | 1.9 | Low | 2017-01-19 | 2016-12-23 | View |
Page 15727 of 17672, showing 5 records out of 88360 total, starting on record 78631, ending on 78635