NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
20657  CVE-2016-5387  The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application"s outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.    5.1  Medium  2017-01-19  2016-11-28  View
86193  CVE-2017-9069  In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.    6.5  Medium  2017-06-03  2017-05-30  View
20913  CVE-2016-5704  Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving a comment.    4.3  Medium  2017-01-19  2016-07-05  View
86449  CVE-2016-9735  IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,    Medium  2017-05-27  2017-05-23  View
21169  CVE-2016-6394  Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.    5.8  Medium  2017-01-19  2016-11-28  View

Page 14885 of 17672, showing 5 records out of 88360 total, starting on record 74421, ending on 74425

Actions