NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28494  CVE-2015-8267  The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username.    7.5  High  2017-01-19  2016-11-28  View
28493  CVE-2015-8265  Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it easier for remote attackers to spoof responses via unspecified vectors.    Medium  2017-01-19  2016-11-28  View
28492  CVE-2015-8263  NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port.    Medium  2017-01-19  2016-11-28  View
28491  CVE-2015-8262  Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.    Medium  2017-01-19  2016-11-28  View
28490  CVE-2015-8261  The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.    7.5  High  2017-01-19  2016-01-08  View

Page 2641 of 17672, showing 5 records out of 88360 total, starting on record 13201, ending on 13205

Actions