NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24586 | CVE-2015-2564 | SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php. | 2 | 6.5 | Medium | 2017-01-19 | 2015-03-23 | View | |
24842 | CVE-2015-2864 | Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
25098 | CVE-2015-3200 | mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character. | 2 | 5 | Medium | 2017-01-19 | 2016-12-23 | View | |
25354 | CVE-2015-3707 | The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app. | 2 | 9.3 | High | 2017-01-19 | 2016-11-28 | View | |
25610 | CVE-2015-4094 | The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2016-03-21 | View |
Page 716 of 17672, showing 5 records out of 88360 total, starting on record 3576, ending on 3580