NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25253 | CVE-2015-3409 | Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module. | 2 | 7.2 | High | 2017-01-19 | 2015-06-25 | View | |
| 25252 | CVE-2015-3408 | Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest. | 2 | 10 | High | 2017-01-19 | 2015-05-20 | View | |
| 25251 | CVE-2015-3407 | Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files. | 2 | 5 | Medium | 2017-01-19 | 2015-05-20 | View | |
| 25250 | CVE-2015-3404 | The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates." | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 25249 | CVE-2015-3397 | Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON, arrays, and Internet Explorer 6 or 7. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View |
Page 3313 of 17672, showing 5 records out of 88360 total, starting on record 16561, ending on 16565