CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96382  CVE-2016-9562  Candidate  SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835.  Assigned (20161122)  None (candidate not yet proposed)    View
96383  CVE-2016-9563  Candidate  BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.  Assigned (20161122)  None (candidate not yet proposed)    View
96384  CVE-2016-9564  Candidate  Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only "/" and "." characters.  Assigned (20161122)  None (candidate not yet proposed)    View
96385  CVE-2016-9565  Candidate  MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.  Assigned (20161122)  None (candidate not yet proposed)    View
96386  CVE-2016-9566  Candidate  base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.  Assigned (20161122)  None (candidate not yet proposed)    View

Page 18671 of 20943, showing 5 records out of 104715 total, starting on record 93351, ending on 93355

Actions