NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83232  CVE-2017-5638  The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 mishandles file upload, which allows remote attackers to execute arbitrary commands via a #cmd= string in a crafted Content-Type HTTP header, as exploited in the wild in March 2017.    10  High  2017-07-18  2017-07-17  View
17952  CVE-2016-1598  XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.    3.5  Low  2017-01-19  2016-11-28  View
83488  CVE-2017-6907  An issue was discovered in Open.GL before 2017-03-13. The vulnerability exists due to insufficient filtration of user-supplied data (content) passed to the Open.GL-master/index.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.    4.3  Medium  2017-04-27  2017-03-30  View
18208  CVE-2016-1861  The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1846.    9.3  High  2017-01-19  2016-11-29  View
83744  CVE-2017-5850  httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.    7.8  High  2017-04-27  2017-03-31  View

Page 2199 of 17672, showing 5 records out of 88360 total, starting on record 10991, ending on 10995

Actions