NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23635 | CVE-2015-1274 | Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user"s previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 23891 | CVE-2015-1632 | Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via the msgParam parameter in an authError action, aka "Exchange Error Message Cross Site Scripting Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2015-10-01 | View | |
| 24403 | CVE-2015-2346 | XML external entity (XXE) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote authenticated users to read arbitrary files via the req parameter. | 2 | 4 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 24915 | CVE-2015-2966 | Directory traversal vulnerability in the Droidware UK Explorer+ File Manager application before 2.3.3 for Android allows remote attackers to write to arbitrary files via unspecified vectors. | 2 | 6.4 | Medium | 2017-01-19 | 2015-07-01 | View | |
| 25171 | CVE-2015-3301 | Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php. | 2 | 4 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 2993 of 17672, showing 5 records out of 88360 total, starting on record 14961, ending on 14965