NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88296 | CVE-2014-7954 | Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4.4 allows physically proximate attackers with a direct connection to the target Android device to upload files outside of the sdcard via a .. (dot dot) in a name parameter of an MTP request. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-12 | View | |
88297 | CVE-2015-0249 | The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL). | 2017-07-18 | 2017-07-17 | View | ||||
88298 | CVE-2015-3297 | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests. | 2 | 5 | Medium | 2017-07-18 | 2017-07-14 | View | |
88299 | CVE-2015-5152 | Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack. | 2017-07-18 | 2017-07-17 | View | ||||
88300 | CVE-2016-0238 | IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409 | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-11 | View |
Page 17660 of 17672, showing 5 records out of 88360 total, starting on record 88296, ending on 88300