NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25068 | CVE-2015-3152 | Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-29 | View | |
25324 | CVE-2015-3677 | The LZVN compression feature in AppleFSCompression in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
25580 | CVE-2015-4027 | The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a command parameter in the reporttemplate property in a params JSON object to api/addScan. | 2 | 7.2 | High | 2017-01-19 | 2015-12-18 | View | |
25836 | CVE-2015-4378 | Cross-site scripting (XSS) vulnerability in the Crumbs module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with the "Administer Crumbs" permission to inject arbitrary web script or HTML via a custom breadcrumb separator. | 2 | 2.1 | Low | 2017-01-19 | 2015-06-16 | View | |
26092 | CVE-2015-4770 | Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect availability via vectors related to UNIX filesystem. | 2 | 4.9 | Medium | 2017-01-19 | 2015-08-27 | View |
Page 16350 of 17672, showing 5 records out of 88360 total, starting on record 81746, ending on 81750