NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17147  CVE-2016-0784  Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.    Medium  2017-01-19  2016-04-14  View
17148  CVE-2016-0785  Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.    10  High  2017-01-19  2016-11-28  View
17149  CVE-2016-0787  The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."    4.3  Medium  2017-03-29  2017-03-23  View
17150  CVE-2016-0788  The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.    10  High  2017-01-19  2016-07-14  View
17151  CVE-2016-0789  CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.    4.3  Medium  2017-01-19  2016-07-14  View

Page 15280 of 17672, showing 5 records out of 88360 total, starting on record 76396, ending on 76400

Actions