NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
35342  CVE-2014-8125  XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.    7.5  High  2017-01-19  2015-05-26  View
36622  CVE-2013-0269  The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."    7.5  High  2017-01-18  2016-12-07  View
38926  CVE-2013-3050  SQL injection vulnerability in ZAPms 1.41 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter to product.    7.5  High  2017-01-18  2013-04-15  View
44558  CVE-2012-2866  Google Chrome before 21.0.1180.89 does not properly perform a cast of an unspecified variable during handling of run-in elements, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.    7.5  High  2017-01-19  2016-09-29  View
45070  CVE-2012-3477  SQL injection vulnerability in signup_check.php in NeoInvoice allows remote attackers to execute arbitrary SQL commands via the value parameter in a username action.    7.5  High  2017-01-19  2012-08-27  View

Page 2102 of 17672, showing 5 records out of 88360 total, starting on record 10506, ending on 10510

Actions