NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
18959 | CVE-2016-3081 | Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions. | 2 | 9.3 | High | 2017-01-19 | 2016-11-30 | View | |
18436 | CVE-2016-2162 | Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
17148 | CVE-2016-0785 | Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. | 2 | 10 | High | 2017-01-19 | 2016-11-28 | View | |
38090 | CVE-2013-1965 | Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.1, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect. | 2 | 9.3 | High | 2017-01-18 | 2013-07-26 | View | |
31709 | CVE-2014-3528 | Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm. | 2 | 4 | Medium | 2017-01-19 | 2017-01-06 | View |
Page 1288 of 17672, showing 5 records out of 88360 total, starting on record 6436, ending on 6440