NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
46844  CVE-2012-5807  The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.    5.8  Medium  2017-01-19  2012-11-06  View
47100  CVE-2012-6290  SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.    6.5  Medium  2017-01-19  2014-03-11  View
16637  CVE-2016-0126  Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."    9.3  High  2017-01-19  2016-11-30  View
16893  CVE-2016-0477  Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0476 and CVE-2016-0478. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the (1) repository, (2) workspace, or (3) scenario parameter.    Medium  2017-01-19  2016-12-07  View
17405  CVE-2016-1000156  Mailcwp remote file upload vulnerability incomplete fix v1.100    7.5  High  2017-01-19  2016-12-15  View

Page 15240 of 17672, showing 5 records out of 88360 total, starting on record 76196, ending on 76200

Actions