NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21482 | CVE-2016-6847 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when calling the related cover URL. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-16 | View | |
21994 | CVE-2016-7997 | The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer. | 2 | 5 | Medium | 2017-01-30 | 2017-01-23 | View | |
22506 | CVE-2016-9882 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs the credentials returned from service brokers in Cloud Controller system component logs. These logs are written to disk and often sent to a log aggregator via syslog. | 2 | 5 | Medium | 2017-01-19 | 2017-01-18 | View | |
22762 | CVE-2015-0279 | JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter. | 2 | 6.8 | Medium | 2017-01-19 | 2016-08-23 | View | |
88298 | CVE-2015-3297 | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests. | 2 | 5 | Medium | 2017-07-18 | 2017-07-14 | View |
Page 16901 of 17672, showing 5 records out of 88360 total, starting on record 84501, ending on 84505