NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 17628 | CVE-2016-1181 | ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 17629 | CVE-2016-1182 | ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899. | 2 | 6.4 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 17630 | CVE-2016-1183 | NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname. | 2 | 4.3 | Medium | 2017-01-19 | 2016-06-23 | View | |
| 85104 | CVE-2016-1184 | Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-26 | View | |
| 17631 | CVE-2016-1185 | The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application. | 2 | 2.6 | Low | 2017-03-18 | 2017-03-14 | View |
Page 15422 of 17672, showing 5 records out of 88360 total, starting on record 77106, ending on 77110