NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
19752  CVE-2016-4040  SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.    6.5  Medium  2017-01-19  2016-04-22  View
85288  CVE-2016-2555  SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.    7.5  High  2017-04-27  2017-04-19  View
20008  CVE-2016-4323  A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability.    5.8  Medium  2017-01-19  2017-01-10  View
85544  CVE-2017-8362  The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.    4.3  Medium  2017-05-07  2017-05-05  View
20264  CVE-2016-4694  The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application"s outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue, a related issue to CVE-2016-5387.    7.5  High  2017-01-19  2016-11-28  View

Page 2746 of 17672, showing 5 records out of 88360 total, starting on record 13726, ending on 13730

Actions