NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27719 | CVE-2015-6968 | Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.2 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .pht or (2) .phtml extension. | 2 | 6.5 | Medium | 2017-01-19 | 2015-09-16 | View | |
| 28231 | CVE-2015-7783 | Cross-site scripting (XSS) vulnerability in Let"s PHP! p++BBS before 4.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2015-12-28 | View | |
| 28487 | CVE-2015-8252 | The Frontel protocol before 3 on RSI Video Technologies Videofied devices sends a cleartext serial number, which allows remote attackers to determine a hardcoded key by sniffing the network and performing a "jumbled up" calculation with this number. | 2 | 4.3 | Medium | 2017-01-19 | 2015-12-28 | View | |
| 29511 | CVE-2014-0627 | The SSLEngine API implementation in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to trigger the selection of a weak cipher suite by using the wrap method during a certain incomplete-handshake state. | 2 | 5 | Medium | 2017-01-19 | 2014-02-18 | View | |
| 30023 | CVE-2014-1347 | Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations. | 2 | 4.4 | Medium | 2017-01-19 | 2014-05-19 | View |
Page 2577 of 17672, showing 5 records out of 88360 total, starting on record 12881, ending on 12885