NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22509  CVE-2016-9888  An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.    4.3  Medium  2017-01-19  2016-12-14  View
22765  CVE-2015-0284  Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.    3.5  Low  2017-01-19  2016-04-18  View
23021  CVE-2015-0548  The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.    Medium  2017-01-19  2016-12-27  View
23277  CVE-2015-0840  The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).    4.3  Medium  2017-01-19  2017-01-02  View
23533  CVE-2015-1147  Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.    Medium  2017-01-19  2015-09-17  View

Page 16552 of 17672, showing 5 records out of 88360 total, starting on record 82756, ending on 82760

Actions