NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23844 | CVE-2015-1571 | ** DISPUTED ** The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers" installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says "The Fortinet_Factory certificate is unique to each device ... An attacker cannot therefore stage a MitM attack." | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-22 | View | |
| 24100 | CVE-2015-1897 | Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1898. | 2 | 7.2 | High | 2017-01-19 | 2016-12-08 | View | |
| 24356 | CVE-2015-2267 | mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value. | 2 | 4 | Medium | 2017-01-19 | 2015-06-02 | View | |
| 24612 | CVE-2015-2591 | Unspecified vulnerability in the PeopleSoft Enteprise Portal - Interaction Hub component in Oracle PeopleSoft Products 9.1.00 allows remote authenticated users to affect integrity via unknown vectors related to Enterprise Portal. | 2 | 4 | Medium | 2017-01-19 | 2015-07-16 | View | |
| 24868 | CVE-2015-2906 | ** DISPUTED ** Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, store SSH private keys that are the same across different customers" installations, which makes it easier for remote attackers to obtain access by leveraging knowledge of a private key from another installation. NOTE: the vendor states "This was a flaw for the developer/debugging devices (again not possible in production versions)." | 2 | 9 | High | 2017-01-19 | 2015-08-24 | View |
Page 2194 of 17672, showing 5 records out of 88360 total, starting on record 10966, ending on 10970