NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22765  CVE-2015-0284  Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.    3.5  Low  2017-01-19  2016-04-18  View
23021  CVE-2015-0548  The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.    Medium  2017-01-19  2016-12-27  View
23277  CVE-2015-0840  The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).    4.3  Medium  2017-01-19  2017-01-02  View
23533  CVE-2015-1147  Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.    Medium  2017-01-19  2015-09-17  View
23789  CVE-2015-1478  Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifieds.    4.3  Medium  2017-01-19  2015-02-04  View

Page 16065 of 17672, showing 5 records out of 88360 total, starting on record 80321, ending on 80325

Actions