NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27172 | CVE-2015-6164 | Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability." | 2 | 6.8 | Medium | 2017-01-19 | 2015-12-09 | View | |
| 27428 | CVE-2015-6535 | Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter). | 2 | 3.5 | Low | 2017-01-19 | 2016-12-21 | View | |
| 27684 | CVE-2015-6908 | The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 27940 | CVE-2015-7282 | ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 28196 | CVE-2015-7725 | Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allow remote authenticated users to execute arbitrary SQL commands via the (1) remoteSourceName in the dropCredentials function or unspecified vectors in the (2) setTraceLevelsForXsApps, (3) _modifyUser, or (4) _newUser function, aka SAP Security Notes 2153898 and 2153765. | 2 | 6.5 | Medium | 2017-01-19 | 2015-10-16 | View |
Page 2832 of 17672, showing 5 records out of 88360 total, starting on record 14156, ending on 14160