NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86336 | CVE-2015-5211 | Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response. | 2 | 9.3 | High | 2017-06-12 | 2017-06-08 | View | |
86344 | CVE-2015-5609 | Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a full pathname in the file parameter to download.php. | 2 | 6.4 | Medium | 2017-06-12 | 2017-06-08 | View | |
86345 | CVE-2015-5682 | upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable. | 2 | 5 | Medium | 2017-06-12 | 2017-06-08 | View | |
86350 | CVE-2016-0761 | Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host. | 2 | 10 | High | 2017-06-12 | 2017-06-08 | View | |
86353 | CVE-2016-10073 | The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request. | 2 | 5 | Medium | 2017-06-12 | 2017-06-08 | View |
Page 16154 of 17672, showing 5 records out of 88360 total, starting on record 80766, ending on 80770