NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20091 | CVE-2016-4437 | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
21459 | CVE-2016-6802 | Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path. | 2 | 5 | Medium | 2017-01-19 | 2016-09-21 | View | |
60254 | CVE-2006-1546 | Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a "org.apache.struts.taglib.html.Constants.CANCEL" parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
78055 | CVE-2001-0590 | Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary "jsp" files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0). | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
88083 | CVE-2017-7660 | Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a malicious node. This can trick the nodes in cluster to believe that the malicious node is a member of the cluster. So, if Solr users have enabled BasicAuth authentication mechanism using the BasicAuthPlugin or if the user has implemented a custom Authentication plugin, which does not implement either HttpClientInterceptorPlugin or HttpClientBuilderPlugin, his/her servers are vulnerable to this attack. Users who only use SSL without basic authentication or those who use Kerberos are not affected. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 1283 of 17672, showing 5 records out of 88360 total, starting on record 6411, ending on 6415