NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22509 | CVE-2016-9888 | An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-14 | View | |
22765 | CVE-2015-0284 | Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811. | 2 | 3.5 | Low | 2017-01-19 | 2016-04-18 | View | |
23021 | CVE-2015-0548 | The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-12-27 | View | |
23277 | CVE-2015-0840 | The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc). | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-02 | View | |
23533 | CVE-2015-1147 | Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network. | 2 | 5 | Medium | 2017-01-19 | 2015-09-17 | View |
Page 16552 of 17672, showing 5 records out of 88360 total, starting on record 82756, ending on 82760