NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22282 | CVE-2016-9134 | Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/expPaginator.php" affecting the order parameter. Impact is Information Disclosure. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
82115 | CVE-2016-9132 | In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure. | 2017-02-08 | 2017-02-01 | View | ||||
22281 | CVE-2016-9131 | named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query. | 2 | 5 | Medium | 2017-01-19 | 2017-01-13 | View | |
83996 | CVE-2016-9130 | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn"t properly escaped when displayed in the campaign-zone.php script. | 2 | 3.5 | Low | 2017-03-29 | 2017-03-29 | View | |
83995 | CVE-2016-9129 | Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username. | 2 | 5 | Medium | 2017-03-29 | 2017-03-29 | View |
Page 1085 of 17672, showing 5 records out of 88360 total, starting on record 5421, ending on 5425