NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
41938  CVE-2013-7175  Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.    6.5  Medium  2017-01-18  2016-12-30  View
25555  CVE-2015-3983  The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.    4.3  Medium  2017-01-19  2016-12-30  View
29139  CVE-2014-0230  Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.    7.8  High  2017-01-19  2016-12-30  View
39891  CVE-2013-4258  Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to syslog.    7.5  High  2017-01-18  2016-12-30  View
36308  CVE-2014-9709  The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.    Medium  2017-01-19  2016-12-30  View

Page 14762 of 17672, showing 5 records out of 88360 total, starting on record 73806, ending on 73810

Actions