NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23795  CVE-2015-1484  Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.    6.9  Medium  2017-01-19  2017-01-02  View
24051  CVE-2015-1816  Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.    Medium  2017-01-19  2015-10-16  View
24307  CVE-2015-2171  Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data.    7.5  High  2017-01-19  2016-12-02  View
24563  CVE-2015-2532  Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability."    4.3  Medium  2017-01-19  2016-12-21  View
24819  CVE-2015-2839  The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.    4.3  Medium  2017-01-19  2016-12-02  View

Page 16826 of 17672, showing 5 records out of 88360 total, starting on record 84126, ending on 84130

Actions