NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
26610 | CVE-2015-5458 | Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess parameter. | 2 | 6.8 | Medium | 2017-01-19 | 2015-08-11 | View | |
26866 | CVE-2015-5802 | WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-21 | View | |
27122 | CVE-2015-6106 | The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2010, Lync 2013 SP1, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability." | 2 | 9.3 | High | 2017-01-19 | 2015-12-09 | View | |
27378 | CVE-2015-6467 | Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin. | 2 | 9.3 | High | 2017-01-19 | 2016-01-20 | View | |
27634 | CVE-2015-6807 | Cross-site scripting (XSS) vulnerability in the Mass Contact module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer mass contact" permission to inject arbitrary web script or HTML via a category label. | 2 | 2.1 | Low | 2017-01-19 | 2015-09-04 | View |
Page 16859 of 17672, showing 5 records out of 88360 total, starting on record 84291, ending on 84295