NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 86923 | CVE-2017-2773 | An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users in multiple components included in PCF Elastic Runtime, aka an Unauthenticated JWT signing algorithm in multiple components issue. | 2 | 7.5 | High | 2017-07-18 | 2017-07-03 | View | |
| 21899 | CVE-2016-7791 | Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil "exploit.tar.gz" file to the website, then extract it by visiting "/install/index.php?install_sample=../../files/exploit", which leads to arbitrary code execution. | 2 | 7.5 | High | 2017-01-19 | 2017-01-13 | View | |
| 22411 | CVE-2016-9565 | MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796. | 2 | 7.5 | High | 2017-01-19 | 2016-12-16 | View | |
| 24715 | CVE-2015-2712 | The asm.js implementation in Mozilla Firefox before 38.0 does not properly determine heap lengths during identification of cases in which bounds checking may be safely skipped, which allows remote attackers to trigger out-of-bounds write operations and possibly execute arbitrary code, or trigger out-of-bounds read operations and possibly obtain sensitive information from process memory, via crafted JavaScript. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View | |
| 28555 | CVE-2015-8387 | PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | 2 | 7.5 | High | 2017-01-19 | 2016-12-29 | View |
Page 14381 of 17672, showing 5 records out of 88360 total, starting on record 71901, ending on 71905