NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
24603  CVE-2015-2582  Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS.    Medium  2017-01-19  2016-12-21  View
24859  CVE-2015-2897  Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session.    10  High  2017-01-19  2015-08-11  View
25115  CVE-2015-3224  request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client"s IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.    4.3  Medium  2017-01-19  2016-12-02  View
25371  CVE-2015-3724  CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723.    6.8  Medium  2017-01-19  2016-12-30  View
25627  CVE-2015-4135  Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter.    4.3  Medium  2017-01-19  2016-12-30  View

Page 1650 of 17672, showing 5 records out of 88360 total, starting on record 8246, ending on 8250

Actions