NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23831  CVE-2015-1558  Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.    3.5  Low  2017-01-19  2015-02-09  View
28439  CVE-2015-8105  Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.    3.5  Low  2017-01-19  2016-12-02  View
39959  CVE-2013-4340  wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.    3.5  Low  2017-01-18  2013-10-02  View
40471  CVE-2013-5001  Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.    3.5  Low  2017-01-18  2013-07-31  View
41751  CVE-2013-6892  WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.    3.5  Low  2017-01-18  2016-08-26  View

Page 2557 of 17672, showing 5 records out of 88360 total, starting on record 12781, ending on 12785

Actions