NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24827 | CVE-2015-2847 | Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream. | 2 | 5 | Medium | 2017-01-19 | 2015-07-27 | View | |
25083 | CVE-2015-3181 | files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked. | 2 | 4 | Medium | 2017-01-19 | 2016-12-30 | View | |
25339 | CVE-2015-3692 | Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging root privileges. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-05 | View | |
25595 | CVE-2015-4060 | Heap-based buffer overflow in the TermProxy (WLTermProxyService.exe) service in Wavelink ConnectPro allows remote attackers to execute arbitrary code via a large HTTP header. | 2 | 10 | High | 2017-01-19 | 2016-12-05 | View | |
25851 | CVE-2015-4393 | The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename. | 2 | 6 | Medium | 2017-01-19 | 2016-06-09 | View |
Page 17371 of 17672, showing 5 records out of 88360 total, starting on record 86851, ending on 86855