NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23344  CVE-2015-0922  McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers" installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.    Medium  2017-01-19  2017-01-02  View
23856  CVE-2015-1585  Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account.    6.8  Medium  2017-01-19  2015-02-20  View
24112  CVE-2015-1909  The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.    Medium  2017-01-19  2015-05-26  View
24880  CVE-2015-2925  The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."    6.9  Medium  2017-01-19  2016-12-07  View
25136  CVE-2015-3247  Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.    6.9  Medium  2017-01-19  2016-12-21  View

Page 1747 of 17672, showing 5 records out of 88360 total, starting on record 8731, ending on 8735

Actions