NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24825 | CVE-2015-2845 | The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATH_INFO. | 2 | 10 | High | 2017-01-19 | 2016-12-02 | View | |
25081 | CVE-2015-3179 | login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-30 | View | |
25337 | CVE-2015-3690 | The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
25593 | CVE-2015-4053 | The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file. | 2 | 2.1 | Low | 2017-01-19 | 2015-06-25 | View | |
25849 | CVE-2015-4391 | Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of users for requests that delete reports via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-06-09 | View |
Page 16884 of 17672, showing 5 records out of 88360 total, starting on record 84416, ending on 84420