NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86336  CVE-2015-5211  Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.    9.3  High  2017-06-12  2017-06-08  View
86344  CVE-2015-5609  Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a full pathname in the file parameter to download.php.    6.4  Medium  2017-06-12  2017-06-08  View
86345  CVE-2015-5682  upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.    Medium  2017-06-12  2017-06-08  View
86350  CVE-2016-0761  Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host.    10  High  2017-06-12  2017-06-08  View
86353  CVE-2016-10073  The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.    Medium  2017-06-12  2017-06-08  View

Page 16154 of 17672, showing 5 records out of 88360 total, starting on record 80766, ending on 80770

Actions