NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27012 | CVE-2015-5957 | Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name. | 2 | 10 | High | 2017-01-19 | 2016-11-28 | View | |
| 27011 | CVE-2015-5956 | The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2) redirect_url parameter to index.php. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-21 | View | |
| 27010 | CVE-2015-5955 | ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie information by reading authentication headers. | 2 | 5 | Medium | 2017-01-19 | 2015-10-30 | View | |
| 27009 | CVE-2015-5954 | The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder. | 2 | 4 | Medium | 2017-01-19 | 2015-10-22 | View | |
| 27008 | CVE-2015-5953 | Cross-site scripting (XSS) vulnerability in the activity application in ownCloud Server before 7.0.5 and 8.0.x before 8.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a " (double quote) character in a filename in a shared folder. | 2 | 3.5 | Low | 2017-01-19 | 2015-10-22 | View |
Page 2951 of 17672, showing 5 records out of 88360 total, starting on record 14751, ending on 14755