NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25067 | CVE-2015-3148 | cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
25323 | CVE-2015-3676 | AppleGraphicsControl in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information via a crafted app. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
25579 | CVE-2015-4026 | The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | 2 | 7.5 | High | 2017-01-19 | 2016-12-30 | View | |
25835 | CVE-2015-4377 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with the "create petition" permission to inject arbitrary web script or HTML via unknown vectors. | 2 | 2.1 | Low | 2017-01-19 | 2015-06-17 | View | |
26091 | CVE-2015-4769 | Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4767. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-21 | View |
Page 16282 of 17672, showing 5 records out of 88360 total, starting on record 81406, ending on 81410