NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
19006 | CVE-2016-3161 | For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-3161 ID is for the GameStream unquoted service path. | 2 | 7.2 | High | 2017-01-19 | 2016-12-14 | View | |
19007 | CVE-2016-3162 | The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files. | 2 | 6.5 | Medium | 2017-01-19 | 2016-04-22 | View | |
19008 | CVE-2016-3163 | The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method. | 2 | 5 | Medium | 2017-01-19 | 2016-04-18 | View | |
19009 | CVE-2016-3164 | Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation. | 2 | 5.8 | Medium | 2017-01-19 | 2016-04-12 | View | |
19010 | CVE-2016-3165 | The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition. | 2 | 5 | Medium | 2017-01-19 | 2016-04-12 | View |
Page 15726 of 17672, showing 5 records out of 88360 total, starting on record 78626, ending on 78630