NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26445 | CVE-2015-5234 | IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26444 | CVE-2015-5233 | Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs. | 2 | 6 | Medium | 2017-01-19 | 2016-04-20 | View | |
| 86769 | CVE-2015-5232 | Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197. | 2 | 9.3 | High | 2017-06-18 | 2017-06-14 | View | |
| 26443 | CVE-2015-5231 | The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access. | 2 | 2.1 | Low | 2017-01-19 | 2016-06-30 | View | |
| 26442 | CVE-2015-5229 | The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 3067 of 17672, showing 5 records out of 88360 total, starting on record 15331, ending on 15335