NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22765 | CVE-2015-0284 | Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811. | 2 | 3.5 | Low | 2017-01-19 | 2016-04-18 | View | |
23021 | CVE-2015-0548 | The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-12-27 | View | |
23277 | CVE-2015-0840 | The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc). | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-02 | View | |
23533 | CVE-2015-1147 | Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network. | 2 | 5 | Medium | 2017-01-19 | 2015-09-17 | View | |
23789 | CVE-2015-1478 | Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifieds. | 2 | 4.3 | Medium | 2017-01-19 | 2015-02-04 | View |
Page 16065 of 17672, showing 5 records out of 88360 total, starting on record 80321, ending on 80325