NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25981 | CVE-2015-4591 | eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-10 | View | |
| 25980 | CVE-2015-4590 | The extractFrom function in Internals/QuotedString.cpp in Arduino JSON before 4.5 allows remote attackers to cause a denial of service (crash) via a JSON string with a (backslash) followed by a terminator, as demonstrated by "\ ", which triggers a buffer overflow and over-read. | 2 | 5 | Medium | 2017-01-19 | 2015-06-23 | View | |
| 25979 | CVE-2015-4588 | Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-27 | View | |
| 25978 | CVE-2015-4587 | Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to inject arbitrary web script or HTML via the "Custom application" field in the "port triggering" menu. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 25977 | CVE-2015-4586 | Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h.HOL allows remote attackers to hijack the authentication of administrators for requests that create a user account via an add_user action in a request to password.cmd. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 3162 of 17672, showing 5 records out of 88360 total, starting on record 15806, ending on 15810