NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25253  CVE-2015-3409  Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.    7.2  High  2017-01-19  2015-06-25  View
25252  CVE-2015-3408  Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest.    10  High  2017-01-19  2015-05-20  View
25251  CVE-2015-3407  Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.    Medium  2017-01-19  2015-05-20  View
25250  CVE-2015-3404  The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates."    Medium  2017-01-19  2016-12-05  View
25249  CVE-2015-3397  Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON, arrays, and Internet Explorer 6 or 7.    4.3  Medium  2017-01-19  2016-12-05  View

Page 3313 of 17672, showing 5 records out of 88360 total, starting on record 16561, ending on 16565

Actions