NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
23047 | CVE-2015-0581 | The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880. | 2 | 7.5 | High | 2017-01-19 | 2015-09-17 | View | |
23303 | CVE-2015-0877 | Unrestricted file upload vulnerability in app/lib/mlf.pl in C-BOARD Moyuku before 1.03b3 allows remote attackers to execute arbitrary code by uploading a file with a character in its name. | 2 | 7.5 | High | 2017-01-19 | 2015-04-06 | View | |
23559 | CVE-2015-1188 | The certificate verification functions in the HNDS service in Swisscom Centro Grande (ADB) DSL routers with firmware before 6.14.00 allows remote attackers to access the management functions via unknown vectors. | 2 | 10 | High | 2017-01-19 | 2015-05-21 | View | |
23815 | CVE-2015-1514 | Multiple SQL injection vulnerabilities in FancyFon FAMOC before 3.17.4 allow (1) remote attackers to execute arbitrary SQL commands via the device ID REST parameter (PATH_INFO) to /ajax.php or (2) remote authenticated users to execute arbitrary SQL commands via the order parameter to index.php. | 2 | 7.5 | High | 2017-01-19 | 2015-02-09 | View | |
24071 | CVE-2015-1851 | OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-27 | View |
Page 862 of 17672, showing 5 records out of 88360 total, starting on record 4306, ending on 4310