NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
27676 | CVE-2015-6858 | HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
27932 | CVE-2015-7254 | Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
28188 | CVE-2015-7707 | Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. | 2 | 6.5 | Medium | 2017-01-19 | 2015-10-06 | View | |
28444 | CVE-2015-8125 | Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component. | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View | |
28700 | CVE-2015-8603 | Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the serendipity[entry_id] parameter in an "edit" admin action to serendipity_admin.php. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-07 | View |
Page 1713 of 17672, showing 5 records out of 88360 total, starting on record 8561, ending on 8565