NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
36086 | CVE-2014-9375 | Directory traversal vulnerability in the LibraryFileUploadServlet servlet in Lexmark Markvision Enterprise allows remote authenticated users to write to and execute arbitrary files via a .. (dot dot) in a file path in a ZIP archive. | 2 | 9 | High | 2017-01-19 | 2015-02-17 | View | |
36342 | CVE-2014-9752 | Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension as a customicon for a new course, then accessing it via a direct request to the file in content/. | 2 | 6.5 | Medium | 2017-01-19 | 2015-11-17 | View | |
36598 | CVE-2013-0242 | Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters. | 2 | 5 | Medium | 2017-01-18 | 2017-01-06 | View | |
36854 | CVE-2013-0527 | The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the screen of an unattended workstation. | 2 | 1.9 | Low | 2017-01-18 | 2013-06-24 | View | |
37110 | CVE-2013-0840 | Google Chrome before 24.0.1312.56 does not validate URLs during the opening of new windows, which has unspecified impact and remote attack vectors. | 2 | 10 | High | 2017-01-18 | 2016-10-13 | View |
Page 17040 of 17672, showing 5 records out of 88360 total, starting on record 85196, ending on 85200