NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
88000  CVE-2017-5361  Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack.    4.3  Medium  2017-07-18  2017-07-07  View
22720  CVE-2015-0219  Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.    Medium  2017-01-19  2016-12-21  View
88256  CVE-2017-9894  XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a User Mode Write AV starting at Xfpx!gffGetFormatInfo+0x0000000000029272.    4.6  Medium  2017-07-18  2017-07-10  View
22976  CVE-2015-0501  Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.    5.7  Medium  2017-01-19  2017-01-02  View
24768  CVE-2015-2769  Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.    6.8  Medium  2017-01-19  2015-03-30  View

Page 15422 of 17672, showing 5 records out of 88360 total, starting on record 77106, ending on 77110

Actions