NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23635  CVE-2015-1274  Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user"s previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.    6.8  Medium  2017-01-19  2016-12-02  View
23891  CVE-2015-1632  Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via the msgParam parameter in an authError action, aka "Exchange Error Message Cross Site Scripting Vulnerability."    4.3  Medium  2017-01-19  2015-10-01  View
24403  CVE-2015-2346  XML external entity (XXE) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote authenticated users to read arbitrary files via the req parameter.    Medium  2017-01-19  2016-12-02  View
24915  CVE-2015-2966  Directory traversal vulnerability in the Droidware UK Explorer+ File Manager application before 2.3.3 for Android allows remote attackers to write to arbitrary files via unspecified vectors.    6.4  Medium  2017-01-19  2015-07-01  View
25171  CVE-2015-3301  Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.    Medium  2017-01-19  2016-11-28  View

Page 2993 of 17672, showing 5 records out of 88360 total, starting on record 14961, ending on 14965

Actions