NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
19764  CVE-2016-4059  Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.    6.8  Medium  2017-01-19  2016-11-28  View
86324  CVE-2014-9970  jasypt before 1.9.2 allows a timing attack against the password hash comparison.    Medium  2017-06-04  2017-05-31  View
86580  CVE-2017-1319  IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731.    Medium  2017-07-18  2017-07-07  View
21300  CVE-2016-6616  An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.    6.8  Medium  2017-01-19  2016-12-23  View
87092  CVE-2017-9463  The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The user_list_backend.php component is affected: values of the iDisplayStart & iDisplayLength parameters are not sanitized; these are used to construct a SQL query and retrieve a list of registered users into the application.    Medium  2017-06-23  2017-06-19  View

Page 1883 of 17672, showing 5 records out of 88360 total, starting on record 9411, ending on 9415

Actions