NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
20911  CVE-2016-5702  phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.    4.3  Medium  2017-01-19  2016-07-05  View
86447  CVE-2016-8587  dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/.    Medium  2017-05-27  2017-05-24  View
86703  CVE-2017-9473  In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View
86959  CVE-2017-6682  A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information: CSCvc76620. Known Affected Releases: 2.2(9.76).    6.5  Medium  2017-06-28  2017-06-23  View
21679  CVE-2016-7152  The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.    Medium  2017-01-19  2016-11-28  View

Page 14817 of 17672, showing 5 records out of 88360 total, starting on record 74081, ending on 74085

Actions