NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25067  CVE-2015-3148  cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.    Medium  2017-01-19  2017-01-02  View
25323  CVE-2015-3676  AppleGraphicsControl in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information via a crafted app.    4.3  Medium  2017-01-19  2016-11-28  View
25579  CVE-2015-4026  The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.    7.5  High  2017-01-19  2016-12-30  View
25835  CVE-2015-4377  Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with the "create petition" permission to inject arbitrary web script or HTML via unknown vectors.    2.1  Low  2017-01-19  2015-06-17  View
26091  CVE-2015-4769  Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4767.    3.5  Low  2017-01-19  2016-12-21  View

Page 16282 of 17672, showing 5 records out of 88360 total, starting on record 81406, ending on 81410

Actions