NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 22351 | CVE-2016-9287 | In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter "$term" used directly in SQL. Impact is a SQL injection. | 2 | 7.5 | High | 2017-01-19 | 2016-11-29 | View | |
| 23375 | CVE-2015-0979 | Heap-based buffer overflow in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via a crafted packet. | 2 | 9 | High | 2017-01-19 | 2015-03-16 | View | |
| 24911 | CVE-2015-2962 | CGI RESCUE BloBee 1.20 and earlier allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View | |
| 25167 | CVE-2015-3292 | The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors. | 2 | 10 | High | 2017-01-19 | 2016-12-02 | View | |
| 25423 | CVE-2015-3776 | IOKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption and application crash) via a malformed plist. | 2 | 9.3 | High | 2017-01-19 | 2016-12-23 | View |
Page 2459 of 17672, showing 5 records out of 88360 total, starting on record 12291, ending on 12295