NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
16329 | CVE-2010-5094 | The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete index.php and "disrupt mod_rewrite-less URL routing." | 2 | 5 | Medium | 2017-01-18 | 2012-08-27 | View | |
81865 | CVE-2016-6495 | NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP access. | 2 | 4.3 | Medium | 2017-02-28 | 2017-02-24 | View | |
16841 | CVE-2016-0425 | Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Monitoring and Diagnostics. | 2 | 6 | Medium | 2017-01-19 | 2016-12-07 | View | |
17097 | CVE-2016-0706 | Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and consequently discover session ID values, via a crafted web application. | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
82633 | CVE-2017-6304 | An issue was discovered in ytnef before 1.9.1. This is related to a patch described as 7 of 9. Out of Bounds read. | 2 | 6.8 | Medium | 2017-03-18 | 2017-03-01 | View |
Page 15730 of 17672, showing 5 records out of 88360 total, starting on record 78646, ending on 78650