NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17950  CVE-2016-1595  LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.    Medium  2017-01-19  2016-12-02  View
83486  CVE-2017-6905  An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (disable_choose) passed to the concrete5-legacy-master/web/concrete/tools/files/search_dialog.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.    4.3  Medium  2017-03-29  2017-03-23  View
18206  CVE-2016-1859  The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.    6.8  Medium  2017-01-19  2016-11-30  View
18462  CVE-2016-2193  PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.    Medium  2017-01-19  2016-04-14  View
83998  CVE-2016-9168  A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.    4.3  Medium  2017-03-29  2017-03-27  View

Page 1097 of 17672, showing 5 records out of 88360 total, starting on record 5481, ending on 5485

Actions