NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
23308 | CVE-2015-0882 | Multiple cross-site scripting (XSS) vulnerabilities in zencart-ja (aka Zen Cart Japanese edition) 1.3 jp through 1.3.0.2 jp8 and 1.5 ja through 1.5.1 ja allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to admin/includes/init_includes/init_sanitize.php and includes/init_includes/init_sanitize.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-02-27 | View | |
23564 | CVE-2015-1195 | The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-28 | View | |
24076 | CVE-2015-1860 | Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-30 | View | |
25356 | CVE-2015-3709 | Race condition in kext tools in Apple OS X before 10.10.4 allows local users to bypass intended signature requirements for kernel extensions by leveraging improper pathname validation. | 2 | 6.9 | Medium | 2017-01-19 | 2016-11-28 | View | |
26124 | CVE-2015-4802 | Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792. | 2 | 4 | Medium | 2017-01-19 | 2016-12-23 | View |
Page 453 of 17672, showing 5 records out of 88360 total, starting on record 2261, ending on 2265