NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
20091  CVE-2016-4437  Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.    6.8  Medium  2017-01-19  2016-11-28  View
20092  CVE-2016-4438  The REST plugin in Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.    7.5  High  2017-01-19  2016-10-06  View
20093  CVE-2016-4439  The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary code on the QEMU host via unspecified vectors.    4.6  Medium  2017-01-19  2016-11-28  View
20094  CVE-2016-4440  arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitrary code on the host OS, via x2APIC mode.    7.2  High  2017-01-19  2016-06-27  View
20095  CVE-2016-4441  The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via unspecified vectors, involving an SCSI command.    2.1  Low  2017-01-19  2016-11-28  View

Page 15951 of 17672, showing 5 records out of 88360 total, starting on record 79751, ending on 79755

Actions