NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24051 | CVE-2015-1816 | Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate. | 2 | 5 | Medium | 2017-01-19 | 2015-10-16 | View | |
24307 | CVE-2015-2171 | Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View | |
24563 | CVE-2015-2532 | Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
24819 | CVE-2015-2839 | The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
25331 | CVE-2015-3684 | The HTTPAuthentication implementation in CFNetwork in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted credentials in a URL. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 16918 of 17672, showing 5 records out of 88360 total, starting on record 84586, ending on 84590