NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23030  CVE-2015-0557  Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.    5.8  Medium  2017-01-19  2016-12-07  View
23286  CVE-2015-0854  App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.    9.3  High  2017-01-19  2017-01-03  View
23542  CVE-2015-1156  The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, does not properly handle the rel attribute in an A element, which allows remote attackers to bypass the Same Origin Policy for a link"s target, and spoof the user interface, via a crafted web site.    4.3  Medium  2017-01-19  2016-11-28  View
23798  CVE-2015-1487  The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafted filename.    5.5  Medium  2017-01-19  2015-08-03  View
24054  CVE-2015-1821  Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.    6.5  Medium  2017-01-19  2016-11-28  View

Page 17098 of 17672, showing 5 records out of 88360 total, starting on record 85486, ending on 85490

Actions