NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
19764 | CVE-2016-4059 | Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
86324 | CVE-2014-9970 | jasypt before 1.9.2 allows a timing attack against the password hash comparison. | 2 | 5 | Medium | 2017-06-04 | 2017-05-31 | View | |
86580 | CVE-2017-1319 | IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731. | 2 | 5 | Medium | 2017-07-18 | 2017-07-07 | View | |
21300 | CVE-2016-6616 | An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-23 | View | |
87092 | CVE-2017-9463 | The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The user_list_backend.php component is affected: values of the iDisplayStart & iDisplayLength parameters are not sanitized; these are used to construct a SQL query and retrieve a list of registered users into the application. | 2 | 4 | Medium | 2017-06-23 | 2017-06-19 | View |
Page 1883 of 17672, showing 5 records out of 88360 total, starting on record 9411, ending on 9415