NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
27701 | CVE-2015-6932 | VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-21 | View | |
27957 | CVE-2015-7305 | The Scald module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to fields, which allows remote attackers to obtain sensitive atom property information via vectors involving a "debug context." | 2 | 5 | Medium | 2017-01-19 | 2015-09-22 | View | |
28213 | CVE-2015-7760 | libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which allows remote attackers to cause a denial of service (resource consumption) by repeatedly connecting to the SSH port, a different vulnerability than CVE-2015-7761. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
28981 | CVE-2014-0033 | org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-04-25 | View | |
29237 | CVE-2014-0338 | Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-24 | View |
Page 1924 of 17672, showing 5 records out of 88360 total, starting on record 9616, ending on 9620