NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
23795 | CVE-2015-1484 | Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe. | 2 | 6.9 | Medium | 2017-01-19 | 2017-01-02 | View | |
24051 | CVE-2015-1816 | Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate. | 2 | 5 | Medium | 2017-01-19 | 2015-10-16 | View | |
24307 | CVE-2015-2171 | Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View | |
24563 | CVE-2015-2532 | Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
24819 | CVE-2015-2839 | The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View |
Page 16826 of 17672, showing 5 records out of 88360 total, starting on record 84126, ending on 84130