NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 86357 | CVE-2016-2172 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | 1 | 2017-05-27 | 2017-05-22 | View | |||
| 18443 | CVE-2016-2171 | The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API. | 2 | 6.4 | Medium | 2017-01-19 | 2016-04-14 | View | |
| 18442 | CVE-2016-2170 | Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View | |
| 18441 | CVE-2016-2168 | The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check. | 2 | 4 | Medium | 2017-01-19 | 2016-11-30 | View | |
| 18440 | CVE-2016-2167 | The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string. | 2 | 4.9 | Medium | 2017-01-19 | 2016-11-30 | View |
Page 2078 of 17672, showing 5 records out of 88360 total, starting on record 10386, ending on 10390