NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27719  CVE-2015-6968  Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.2 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .pht or (2) .phtml extension.    6.5  Medium  2017-01-19  2015-09-16  View
28231  CVE-2015-7783  Cross-site scripting (XSS) vulnerability in Let"s PHP! p++BBS before 4.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-19  2015-12-28  View
28487  CVE-2015-8252  The Frontel protocol before 3 on RSI Video Technologies Videofied devices sends a cleartext serial number, which allows remote attackers to determine a hardcoded key by sniffing the network and performing a "jumbled up" calculation with this number.    4.3  Medium  2017-01-19  2015-12-28  View
29511  CVE-2014-0627  The SSLEngine API implementation in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to trigger the selection of a weak cipher suite by using the wrap method during a certain incomplete-handshake state.    Medium  2017-01-19  2014-02-18  View
30023  CVE-2014-1347  Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.    4.4  Medium  2017-01-19  2014-05-19  View

Page 2577 of 17672, showing 5 records out of 88360 total, starting on record 12881, ending on 12885

Actions