NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24093 | CVE-2015-1889 | The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure. | 2 | 6.5 | Medium | 2017-01-19 | 2017-01-02 | View | |
24349 | CVE-2015-2244 | Multiple cross-site scripting (XSS) vulnerabilities in Webshop hun 1.062S allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) center, (3) lap, (4) termid, or (5) nyelv_id parameter to index.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-03-10 | View | |
24605 | CVE-2015-2584 | Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-2592. | 2 | 4 | Medium | 2017-01-19 | 2015-07-16 | View | |
24861 | CVE-2015-2899 | Heap-based buffer overflow in the QualifierList retrieve_qualifier_list function in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a long list name in a packet on port 8190. | 2 | 6.8 | Medium | 2017-01-19 | 2015-10-29 | View | |
25117 | CVE-2015-3226 | Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View |
Page 1772 of 17672, showing 5 records out of 88360 total, starting on record 8856, ending on 8860