NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16329  CVE-2010-5094  The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete index.php and "disrupt mod_rewrite-less URL routing."    Medium  2017-01-18  2012-08-27  View
81865  CVE-2016-6495  NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP access.    4.3  Medium  2017-02-28  2017-02-24  View
16841  CVE-2016-0425  Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Monitoring and Diagnostics.    Medium  2017-01-19  2016-12-07  View
17097  CVE-2016-0706  Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and consequently discover session ID values, via a crafted web application.    Medium  2017-01-19  2016-12-05  View
82633  CVE-2017-6304  An issue was discovered in ytnef before 1.9.1. This is related to a patch described as 7 of 9. Out of Bounds read.    6.8  Medium  2017-03-18  2017-03-01  View

Page 15730 of 17672, showing 5 records out of 88360 total, starting on record 78646, ending on 78650

Actions