NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
28187 | CVE-2015-7706 | Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password. | 2 | 4.3 | Medium | 2017-01-19 | 2016-01-13 | View | |
28443 | CVE-2015-8124 | Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
28699 | CVE-2015-8602 | The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node. | 2 | 3.5 | Low | 2017-01-19 | 2015-12-18 | View | |
28955 | CVE-2015-8969 | git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library. | 2 | 10 | High | 2017-01-19 | 2016-11-28 | View | |
29211 | CVE-2014-0311 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0299 and CVE-2014-0305. | 2 | 9.3 | High | 2017-01-19 | 2014-03-12 | View |
Page 1872 of 17672, showing 5 records out of 88360 total, starting on record 9356, ending on 9360