NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83905  CVE-2015-8628  The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to obtain sensitive user login information via crafted links combined with page view statistics.    4.3  Medium  2017-03-29  2017-03-28  View
83907  CVE-2015-8687  Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceTypeID parameter to DeviceType/getDeviceType.do; the (2) policyActionClass or (3) policyActionName parameter to PolicyAction/findPolicyActions.do; the deviceID parameter to (4) SingleDeviceMgmt/getDevice.do or (5) device/editDevice.do; the operation parameter to (6) ajax.do or (7) xmlHttp.do; or the (8) policyAction, (9) policyClass, or (10) policyName parameter to policy/findPolicies.do.    3.5  Low  2017-03-29  2017-03-28  View
17373  CVE-2016-1000124  Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6    7.5  High  2017-03-29  2017-03-28  View
17374  CVE-2016-1000125  Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla    7.5  High  2017-03-29  2017-03-28  View
83934  CVE-2016-10152  The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.          2017-03-29  2017-03-28  View

Page 15788 of 17672, showing 5 records out of 88360 total, starting on record 78936, ending on 78940

Actions