NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
39384  CVE-2013-3617  The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.    3.5  Low  2017-01-18  2013-11-21  View
39983  CVE-2013-4369  The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.    1.9  Low  2017-01-18  2017-01-06  View
20420  CVE-2016-5000  The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.    4.3  Medium  2017-02-15  2017-02-10  View
21965  CVE-2016-7943  The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.    7.5  High  2017-01-19  2016-12-14  View
63998  CVE-2006-5397  The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor.    2.1  Low  2016-12-20  2011-03-07  View

Page 2604 of 17672, showing 5 records out of 88360 total, starting on record 13016, ending on 13020

Actions