NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25650 | CVE-2015-4163 | GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOP_setup_table or GNTTABOP_set_version. | 2 | 4.9 | Medium | 2017-01-19 | 2016-12-30 | View | |
25906 | CVE-2015-4483 | Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
26162 | CVE-2015-4841 | Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM IP2014 and IP2015 allows remote attackers to affect confidentiality via unknown vectors related to Services. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
26418 | CVE-2015-5189 | Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated. | 2 | 4.9 | Medium | 2017-01-19 | 2015-09-04 | View | |
27186 | CVE-2015-6238 | Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix parameter in the google-analyticator page to wp-admin/admin.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-23 | View |
Page 1816 of 17672, showing 5 records out of 88360 total, starting on record 9076, ending on 9080