NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22340 | CVE-2016-9272 | A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service. | 2 | 6.4 | Medium | 2017-01-19 | 2016-11-29 | View | |
82445 | CVE-2016-9244 | A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well. | 2 | 5 | Medium | 2017-02-28 | 2017-02-23 | View | |
76672 | CVE-2000-0429 | A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View | |
83313 | CVE-2017-6381 | A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development dependencies aren't normal installed. You might be vulnerable to this if you are running a version of Drupal before 8.2.2. To be sure you aren't vulnerable, you can remove the <siteroot>/vendor/phpunit directory from your production deployments | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
35762 | CVE-2014-8873 | A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file. | 2 | 10 | High | 2017-01-19 | 2015-11-10 | View |
Page 17333 of 17672, showing 5 records out of 88360 total, starting on record 86661, ending on 86665