NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
19703  CVE-2016-3972  Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.    Medium  2017-01-19  2016-04-19  View
19704  CVE-2016-3973  The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tc~rtc~coll.appl.rtc~wd_chat/Chat#, pressing "Add users", and doing a search, aka SAP Security Note 2255990.    Medium  2017-01-19  2016-11-29  View
19705  CVE-2016-3974  XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.    7.5  High  2017-01-19  2016-11-29  View
19706  CVE-2016-3975  Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigation.testComponent.NavigationURLTester, aka SAP Security Note 2238375.    4.3  Medium  2017-01-19  2016-11-29  View
19707  CVE-2016-3976  Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a .. (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.    Medium  2017-01-19  2016-11-29  View

Page 15869 of 17672, showing 5 records out of 88360 total, starting on record 79341, ending on 79345

Actions