NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27689  CVE-2015-6913  Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman.cgi.    4.3  Medium  2017-01-19  2015-09-14  View
27945  CVE-2015-7287  CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers" installations, which allows remote attackers to execute commands by leveraging knowledge of this PIN and including it in an SMS message.    7.5  High  2017-01-19  2015-11-25  View
28201  CVE-2015-7730  SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.    10  High  2017-01-19  2015-10-16  View
28457  CVE-2015-8152  Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by adding lines to a logging script.    8.5  High  2017-01-19  2016-12-02  View
28713  CVE-2015-8629  The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether "" characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.    2.1  Low  2017-01-19  2016-12-05  View

Page 3173 of 17672, showing 5 records out of 88360 total, starting on record 15861, ending on 15865

Actions