NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84692 | CVE-2017-5648 | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application. | 2 | 6.4 | Medium | 2017-07-18 | 2017-07-10 | View | |
88276 | CVE-2017-9914 | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .bie file, related to a Read Access Violation on Block Data Move starting at Xjbig+0x000000000000121b. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
66005 | CVE-2005-0241 | The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66773 | CVE-2005-1024 | modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
67285 | CVE-2005-1558 | The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 17271 of 17672, showing 5 records out of 88360 total, starting on record 86351, ending on 86355