NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25365 | CVE-2015-3718 | systemstatsd in the System Stats subsystem in Apple OS X before 10.10.4 does not properly interpret data types encountered in interprocess communication, which allows attackers to execute arbitrary code with systemstatsd privileges via a crafted app, related to a "type confusion" issue. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
25621 | CVE-2015-4119 | Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/show_sys_state.php. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-05 | View | |
26645 | CVE-2015-5506 | The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attackers to obtain information about unpublished content via a search. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
26901 | CVE-2015-5837 | PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and install arbitrary extensions via a crafted enterprise app. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
27413 | CVE-2015-6515 | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.2.x before 6.2.4, 6.1.x before 6.1.8, 6.0.x before 6.0.9, and 5.0.x before 5.0.13 and Splunk Light 6.2.x before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via a header. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-19 | View |
Page 774 of 17672, showing 5 records out of 88360 total, starting on record 3866, ending on 3870