NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25198  CVE-2015-3343  Cross-site request forgery (CSRF) vulnerability in the OPAC module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims for requests that remove a mapping via unknown vectors.    6.8  Medium  2017-01-19  2016-12-05  View
25197  CVE-2015-3342  Open redirect vulnerability in the Ubercart Currency Conversion module before 6.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination query parameter.    5.8  Medium  2017-01-19  2015-04-23  View
25196  CVE-2015-3340  Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.    2.9  Low  2017-01-19  2017-01-03  View
25195  CVE-2015-3339  Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.    6.2  Medium  2017-01-19  2016-12-30  View
25194  CVE-2015-3337  Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.    4.3  Medium  2017-01-19  2015-06-25  View

Page 3324 of 17672, showing 5 records out of 88360 total, starting on record 16616, ending on 16620

Actions