NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
23545 | CVE-2015-1159 | Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-30 | View | |
23801 | CVE-2015-1490 | Directory traversal vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via a relative pathname in a client installation package. | 2 | 5.5 | Medium | 2017-01-19 | 2015-08-03 | View | |
24057 | CVE-2015-1829 | Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 10.1.3.5, 11.1.1.7, 11.1.1.9, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect availability via unknown vectors related to Web Listener. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
24313 | CVE-2015-2187 | The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code requirements, which allows remote attackers to cause a denial of service (stack memory corruption and application crash) via a crafted packet. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
24569 | CVE-2015-2543 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View |
Page 16883 of 17672, showing 5 records out of 88360 total, starting on record 84411, ending on 84415