NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 17129 | CVE-2016-0753 | Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 17130 | CVE-2016-0754 | cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a remote file name. | 2 | 5 | Medium | 2017-01-19 | 2016-02-17 | View | |
| 17131 | CVE-2016-0755 | The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 17132 | CVE-2016-0756 | The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 17133 | CVE-2016-0757 | OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image. | 2 | 4 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 15275 of 17672, showing 5 records out of 88360 total, starting on record 76371, ending on 76375