NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 88000 | CVE-2017-5361 | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-07 | View | |
| 22720 | CVE-2015-0219 | Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 88256 | CVE-2017-9894 | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a User Mode Write AV starting at Xfpx!gffGetFormatInfo+0x0000000000029272. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 22976 | CVE-2015-0501 | Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling. | 2 | 5.7 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 24768 | CVE-2015-2769 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2015-03-30 | View |
Page 15422 of 17672, showing 5 records out of 88360 total, starting on record 77106, ending on 77110