NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26414  CVE-2015-5176  The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.    5.8  Medium  2017-01-19  2015-08-11  View
86767  CVE-2015-5175  Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.    Medium  2017-06-18  2017-06-15  View
26413  CVE-2015-5174  Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.    Medium  2017-01-19  2016-12-05  View
26412  CVE-2015-5167  The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API.    Medium  2017-01-19  2016-04-13  View
26411  CVE-2015-5166  Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.    7.2  High  2017-01-19  2016-12-21  View

Page 3074 of 17672, showing 5 records out of 88360 total, starting on record 15366, ending on 15370

Actions