NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 24864 | CVE-2015-2902 | HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 25120 | CVE-2015-3230 | 389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher. | 2 | 7.5 | High | 2017-01-19 | 2015-10-30 | View | |
| 25376 | CVE-2015-3729 | Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, which allows remote attackers to conduct spoofing attacks via a crafted site. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 25632 | CVE-2015-4141 | The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow. | 2 | 4.3 | Medium | 2017-01-19 | 2016-08-16 | View | |
| 25888 | CVE-2015-4460 | Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box before 4.0.0 (r19171) allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via certain vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 2998 of 17672, showing 5 records out of 88360 total, starting on record 14986, ending on 14990