NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27943 | CVE-2015-7285 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allows man-in-the-middle attackers to bypass intended access restrictions via a spoofed HSxx response. | 2 | 5.8 | Medium | 2017-01-19 | 2015-11-25 | View | |
| 28199 | CVE-2015-7728 | Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to inject arbitrary web script or HTML via the username, aka SAP Security Note 2153898. | 2 | 3.5 | Low | 2017-01-19 | 2015-10-16 | View | |
| 28455 | CVE-2015-8150 | Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file. | 2 | 6.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 28711 | CVE-2015-8618 | The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-05-26 | View | |
| 28967 | CVE-2014-0010 | Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields. | 2 | 6.8 | Medium | 2017-01-19 | 2016-04-06 | View |
Page 2378 of 17672, showing 5 records out of 88360 total, starting on record 11886, ending on 11890