NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83666  CVE-2016-1249  The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.    4.3  Medium  2017-03-18  2017-03-13  View
83669  CVE-2016-6485  The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.    Medium  2017-03-18  2017-03-13  View
83417  CVE-2017-6543  Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a reboot). This issue only affects installations on Windows.    Medium  2017-03-18  2017-03-13  View
83418  CVE-2017-6544  Gargaj/wuhu through 2017-03-08 is vulnerable to a reflected XSS in wuhu-master/www_admin/users.php (id parameter).    4.3  Medium  2017-03-18  2017-03-13  View
83679  CVE-2016-9006  IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: C1000264.    3.5  Low  2017-03-18  2017-03-13  View

Page 2027 of 17672, showing 5 records out of 88360 total, starting on record 10131, ending on 10135

Actions