NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26341  CVE-2015-5075  Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators for requests that create an administrative account via a crafted request to index.php/users/create.    6.8  Medium  2017-01-19  2016-12-07  View
26340  CVE-2015-5074  Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a .pht extension.    7.5  High  2017-01-19  2016-12-07  View
26339  CVE-2015-5073  Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.    6.4  Medium  2017-01-19  2016-12-15  View
26338  CVE-2015-5068  XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML request, aka SAP Security Note 2159601.    7.5  High  2017-01-19  2016-12-21  View
26337  CVE-2015-5067  The (1) Cross-System Tools and (2) Data Transfer Workbench in SAP NetWeaver have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors, aka SAP Security Notes 2059659 and 2057982.    7.5  High  2017-01-19  2016-12-29  View

Page 3089 of 17672, showing 5 records out of 88360 total, starting on record 15441, ending on 15445

Actions