NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
24586  CVE-2015-2564  SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php.    6.5  Medium  2017-01-19  2015-03-23  View
24842  CVE-2015-2864  Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision.    Medium  2017-01-19  2016-12-07  View
25098  CVE-2015-3200  mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.    Medium  2017-01-19  2016-12-23  View
25354  CVE-2015-3707  The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.    9.3  High  2017-01-19  2016-11-28  View
25610  CVE-2015-4094  The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    5.8  Medium  2017-01-19  2016-03-21  View

Page 716 of 17672, showing 5 records out of 88360 total, starting on record 3576, ending on 3580

Actions