NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83905 | CVE-2015-8628 | The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to obtain sensitive user login information via crafted links combined with page view statistics. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-28 | View | |
83907 | CVE-2015-8687 | Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceTypeID parameter to DeviceType/getDeviceType.do; the (2) policyActionClass or (3) policyActionName parameter to PolicyAction/findPolicyActions.do; the deviceID parameter to (4) SingleDeviceMgmt/getDevice.do or (5) device/editDevice.do; the operation parameter to (6) ajax.do or (7) xmlHttp.do; or the (8) policyAction, (9) policyClass, or (10) policyName parameter to policy/findPolicies.do. | 2 | 3.5 | Low | 2017-03-29 | 2017-03-28 | View | |
17373 | CVE-2016-1000124 | Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 | 2 | 7.5 | High | 2017-03-29 | 2017-03-28 | View | |
17374 | CVE-2016-1000125 | Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla | 2 | 7.5 | High | 2017-03-29 | 2017-03-28 | View | |
83934 | CVE-2016-10152 | The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache. | 2017-03-29 | 2017-03-28 | View |
Page 15788 of 17672, showing 5 records out of 88360 total, starting on record 78936, ending on 78940