NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26414 | CVE-2015-5176 | The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource. | 2 | 5.8 | Medium | 2017-01-19 | 2015-08-11 | View | |
| 86767 | CVE-2015-5175 | Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service. | 2 | 5 | Medium | 2017-06-18 | 2017-06-15 | View | |
| 26413 | CVE-2015-5174 | Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory. | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 26412 | CVE-2015-5167 | The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API. | 2 | 4 | Medium | 2017-01-19 | 2016-04-13 | View | |
| 26411 | CVE-2015-5166 | Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice. | 2 | 7.2 | High | 2017-01-19 | 2016-12-21 | View |
Page 3074 of 17672, showing 5 records out of 88360 total, starting on record 15366, ending on 15370