NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25115 | CVE-2015-3224 | request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client"s IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
25371 | CVE-2015-3724 | CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-30 | View | |
25627 | CVE-2015-4135 | Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-30 | View | |
26139 | CVE-2015-4818 | Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote authenticated users to affect confidentiality and integrity via vectors related to PIA Core Technology. | 2 | 5.5 | Medium | 2017-01-19 | 2016-12-23 | View | |
26651 | CVE-2015-5512 | The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in a URL. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 992 of 17672, showing 5 records out of 88360 total, starting on record 4956, ending on 4960