NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
45041 | CVE-2012-3446 | Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2012-11-06 | View | |
65888 | CVE-2005-0108 | Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
13573 | CVE-2010-2086 | Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object. | 2 | 4 | Medium | 2017-01-18 | 2010-05-28 | View | |
86989 | CVE-2017-7667 | Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin. | 2 | 5 | Medium | 2017-06-23 | 2017-06-19 | View | |
18442 | CVE-2016-2170 | Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View |
Page 1276 of 17672, showing 5 records out of 88360 total, starting on record 6376, ending on 6380