NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22240  CVE-2016-8903  SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.    6.5  Medium  2017-01-19  2016-11-29  View
22496  CVE-2016-9866  An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.    6.8  Medium  2017-01-19  2016-12-23  View
22752  CVE-2015-0266  The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.    6.5  Medium  2017-01-19  2016-04-13  View
23008  CVE-2015-0534  EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA BSAFE SSL-C 2.8.9 and earlier do not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate"s unsigned portion, a similar issue to CVE-2014-8275.    Medium  2017-01-19  2016-11-28  View
23264  CVE-2015-0825  Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.    4.3  Medium  2017-01-19  2016-12-21  View

Page 15762 of 17672, showing 5 records out of 88360 total, starting on record 78806, ending on 78810

Actions