NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22351  CVE-2016-9287  In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter "$term" used directly in SQL. Impact is a SQL injection.    7.5  High  2017-01-19  2016-11-29  View
23375  CVE-2015-0979  Heap-based buffer overflow in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via a crafted packet.    High  2017-01-19  2015-03-16  View
24911  CVE-2015-2962  CGI RESCUE BloBee 1.20 and earlier allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via unspecified vectors.    7.5  High  2017-01-19  2016-12-02  View
25167  CVE-2015-3292  The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.    10  High  2017-01-19  2016-12-02  View
25423  CVE-2015-3776  IOKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption and application crash) via a malformed plist.    9.3  High  2017-01-19  2016-12-23  View

Page 2459 of 17672, showing 5 records out of 88360 total, starting on record 12291, ending on 12295

Actions