NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25198 | CVE-2015-3343 | Cross-site request forgery (CSRF) vulnerability in the OPAC module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims for requests that remove a mapping via unknown vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 25197 | CVE-2015-3342 | Open redirect vulnerability in the Ubercart Currency Conversion module before 6.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination query parameter. | 2 | 5.8 | Medium | 2017-01-19 | 2015-04-23 | View | |
| 25196 | CVE-2015-3340 | Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request. | 2 | 2.9 | Low | 2017-01-19 | 2017-01-03 | View | |
| 25195 | CVE-2015-3339 | Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped. | 2 | 6.2 | Medium | 2017-01-19 | 2016-12-30 | View | |
| 25194 | CVE-2015-3337 | Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2015-06-25 | View |
Page 3324 of 17672, showing 5 records out of 88360 total, starting on record 16616, ending on 16620