NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24603 | CVE-2015-2582 | Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS. | 2 | 4 | Medium | 2017-01-19 | 2016-12-21 | View | |
24859 | CVE-2015-2897 | Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session. | 2 | 10 | High | 2017-01-19 | 2015-08-11 | View | |
25115 | CVE-2015-3224 | request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client"s IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
25371 | CVE-2015-3724 | CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-30 | View | |
25627 | CVE-2015-4135 | Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-30 | View |
Page 1650 of 17672, showing 5 records out of 88360 total, starting on record 8246, ending on 8250