NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28494 | CVE-2015-8267 | The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
| 28493 | CVE-2015-8265 | Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it easier for remote attackers to spoof responses via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 28492 | CVE-2015-8263 | NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 28491 | CVE-2015-8262 | Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 28490 | CVE-2015-8261 | The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request. | 2 | 7.5 | High | 2017-01-19 | 2016-01-08 | View |
Page 2641 of 17672, showing 5 records out of 88360 total, starting on record 13201, ending on 13205