NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 20420 | CVE-2016-5000 | The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-10 | View | |
| 20676 | CVE-2016-5422 | The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request. | 2 | 6.5 | Medium | 2017-01-19 | 2016-09-08 | View | |
| 86468 | CVE-2017-6512 | Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-07 | View | |
| 86724 | CVE-2014-3498 | The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands. | 2 | 6.5 | Medium | 2017-06-18 | 2017-06-14 | View | |
| 21700 | CVE-2016-7178 | epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (invalid write access and application crash) via a crafted packet. | 2 | 4.3 | Medium | 2017-01-19 | 2016-09-29 | View |
Page 15560 of 17672, showing 5 records out of 88360 total, starting on record 77796, ending on 77800