NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26445  CVE-2015-5234  IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.    6.8  Medium  2017-01-19  2016-12-07  View
26444  CVE-2015-5233  Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs.    Medium  2017-01-19  2016-04-20  View
86769  CVE-2015-5232  Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.    9.3  High  2017-06-18  2017-06-14  View
26443  CVE-2015-5231  The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.    2.1  Low  2017-01-19  2016-06-30  View
26442  CVE-2015-5229  The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.    Medium  2017-01-19  2016-11-28  View

Page 3067 of 17672, showing 5 records out of 88360 total, starting on record 15331, ending on 15335

Actions