NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 40276 | CVE-2013-4730 | Buffer overflow in PCMan"s FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command. | 2 | 10 | High | 2017-01-18 | 2016-12-30 | View | |
| 24405 | CVE-2015-2348 | The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | 2 | 5 | Medium | 2017-01-19 | 2016-12-30 | View | |
| 25173 | CVE-2015-3307 | The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive. | 2 | 7.5 | High | 2017-01-19 | 2016-12-30 | View | |
| 26454 | CVE-2015-5252 | vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | 2 | 5 | Medium | 2017-01-19 | 2016-12-30 | View | |
| 24410 | CVE-2015-2359 | Cross-site scripting (XSS) vulnerability in the web applications in Microsoft Exchange Server 2013 Cumulative Update 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Exchange HTML Injection Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-30 | View |
Page 14718 of 17672, showing 5 records out of 88360 total, starting on record 73586, ending on 73590