NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83695 | CVE-2017-2577 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | 1 | 2017-03-29 | 2017-03-24 | View | |||
83954 | CVE-2016-4504 | A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB"log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per function. | 2 | 6.8 | Medium | 2017-03-29 | 2017-03-24 | View | |
83958 | CVE-2016-5748 | External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in users. | 2 | 2.1 | Low | 2017-03-29 | 2017-03-24 | View | |
83959 | CVE-2016-5749 | NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack. | 2 | 2.1 | Low | 2017-03-29 | 2017-03-24 | View | |
83960 | CVE-2016-5750 | The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users. | 2 | 6.5 | Medium | 2017-03-29 | 2017-03-24 | View |
Page 1928 of 17672, showing 5 records out of 88360 total, starting on record 9636, ending on 9640