NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81642 | CVE-2017-5542 | Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter. | 2 | 4.3 | Medium | 2017-02-07 | 2017-01-26 | View | |
16362 | CVE-2010-5153 | ** DISPUTED ** Race condition in Avira Premium Security Suite 10.0.0.536 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute. | 2 | 6.2 | Medium | 2017-01-18 | 2012-08-29 | View | |
16874 | CVE-2016-0458 | Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via vectors related to Kernel DAX. | 2 | 4 | Medium | 2017-01-19 | 2016-12-07 | View | |
82410 | CVE-2016-8494 | Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme. | 2 | 6.5 | Medium | 2017-02-28 | 2017-02-28 | View | |
17130 | CVE-2016-0754 | cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a remote file name. | 2 | 5 | Medium | 2017-01-19 | 2016-02-17 | View |
Page 16897 of 17672, showing 5 records out of 88360 total, starting on record 84481, ending on 84485