NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17628  CVE-2016-1181  ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.    6.8  Medium  2017-01-19  2016-11-28  View
17629  CVE-2016-1182  ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.    6.4  Medium  2017-01-19  2016-11-28  View
17630  CVE-2016-1183  NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.    4.3  Medium  2017-01-19  2016-06-23  View
85104  CVE-2016-1184  Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.    4.3  Medium  2017-04-27  2017-04-26  View
17631  CVE-2016-1185  The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application.    2.6  Low  2017-03-18  2017-03-14  View

Page 15422 of 17672, showing 5 records out of 88360 total, starting on record 77106, ending on 77110

Actions