NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27431  CVE-2015-6541  Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest.    6.8  Medium  2017-01-19  2016-04-11  View
27687  CVE-2015-6911  SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.    7.5  High  2017-01-19  2015-09-14  View
27943  CVE-2015-7285  CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allows man-in-the-middle attackers to bypass intended access restrictions via a spoofed HSxx response.    5.8  Medium  2017-01-19  2015-11-25  View
28199  CVE-2015-7728  Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to inject arbitrary web script or HTML via the username, aka SAP Security Note 2153898.    3.5  Low  2017-01-19  2015-10-16  View
28455  CVE-2015-8150  Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.    6.3  Medium  2017-01-19  2016-12-05  View

Page 3135 of 17672, showing 5 records out of 88360 total, starting on record 15671, ending on 15675

Actions