NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17948  CVE-2016-1593  Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.    6.5  Medium  2017-01-19  2016-12-02  View
18204  CVE-2016-1857  WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856.    6.8  Medium  2017-01-19  2016-11-30  View
18460  CVE-2016-2190  Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.    Medium  2017-01-19  2016-05-24  View
83996  CVE-2016-9130  Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn"t properly escaped when displayed in the campaign-zone.php script.    3.5  Low  2017-03-29  2017-03-29  View
18716  CVE-2016-2503  The Qualcomm GPU driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28084795 and Qualcomm internal bug CR1006067.    9.3  High  2017-01-19  2016-07-11  View

Page 1705 of 17672, showing 5 records out of 88360 total, starting on record 8521, ending on 8525

Actions