NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83283  CVE-2017-6062  The OpenID Connect Relying Party and OAuth 2.0 Resource Server (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an OIDCUnAuthAction pass configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.    Medium  2017-03-18  2017-03-04  View
83241  CVE-2017-5830  Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.    7.5  High  2017-03-18  2017-03-06  View
83242  CVE-2017-5831  Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.    5.5  Medium  2017-03-18  2017-03-06  View
83243  CVE-2017-5832  Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.    3.5  Low  2017-03-18  2017-03-06  View
83244  CVE-2017-5833  Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.    4.3  Medium  2017-03-18  2017-03-06  View

Page 15626 of 17672, showing 5 records out of 88360 total, starting on record 78126, ending on 78130

Actions