NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25376 | CVE-2015-3729 | Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, which allows remote attackers to conduct spoofing attacks via a crafted site. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 25632 | CVE-2015-4141 | The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow. | 2 | 4.3 | Medium | 2017-01-19 | 2016-08-16 | View | |
| 25888 | CVE-2015-4460 | Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box before 4.0.0 (r19171) allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via certain vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26144 | CVE-2015-4823 | Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1.2.3 allows local users to affect confidentiality via unknown vectors related to Essbase Rapid Deploy. | 2 | 1.2 | Low | 2017-01-19 | 2016-12-23 | View | |
| 26400 | CVE-2015-5149 | Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp. | 2 | 5.5 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 2559 of 17672, showing 5 records out of 88360 total, starting on record 12791, ending on 12795