NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
17950 | CVE-2016-1595 | LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter. | 2 | 4 | Medium | 2017-01-19 | 2016-12-02 | View | |
83486 | CVE-2017-6905 | An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (disable_choose) passed to the concrete5-legacy-master/web/concrete/tools/files/search_dialog.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-23 | View | |
18206 | CVE-2016-1859 | The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-30 | View | |
18462 | CVE-2016-2193 | PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role. | 2 | 5 | Medium | 2017-01-19 | 2016-04-14 | View | |
83998 | CVE-2016-9168 | A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-27 | View |
Page 1097 of 17672, showing 5 records out of 88360 total, starting on record 5481, ending on 5485