NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25620 | CVE-2015-4118 | SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2. | 2 | 6.5 | Medium | 2017-01-19 | 2016-12-05 | View | |
26132 | CVE-2015-4810 | Unspecified vulnerability in Oracle Java SE 7u85 and 8u60 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. | 2 | 6.9 | Medium | 2017-01-19 | 2016-12-23 | View | |
26644 | CVE-2015-5505 | The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
26900 | CVE-2015-5836 | Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-09 | View | |
27412 | CVE-2015-6514 | Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Enterprise 6.2.x before 6.2.4 and Splunk Light 6.2.x before 6.2.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-19 | View |
Page 739 of 17672, showing 5 records out of 88360 total, starting on record 3691, ending on 3695