NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
24583  CVE-2015-2559  Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.    3.5  Low  2017-01-19  2016-08-24  View
24839  CVE-2015-2861  Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitrary users.    6.8  Medium  2017-01-19  2016-12-02  View
25095  CVE-2015-3196  ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.    4.3  Medium  2017-01-19  2016-12-30  View
25351  CVE-2015-3704  runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows attackers to execute arbitrary code in a privileged context via a crafted app.    9.3  High  2017-01-19  2016-12-21  View
25607  CVE-2015-4091  XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to "CIM UPLOAD," aka SAP Security Note 2090851.    7.5  High  2017-01-19  2016-12-05  View

Page 449 of 17672, showing 5 records out of 88360 total, starting on record 2241, ending on 2245

Actions