NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 18443 | CVE-2016-2171 | The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API. | 2 | 6.4 | Medium | 2017-01-19 | 2016-04-14 | View | |
| 18699 | CVE-2016-2486 | mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate the relationship between allocated memory and the frame size, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27793371. | 2 | 9.3 | High | 2017-01-19 | 2016-06-13 | View | |
| 18955 | CVE-2016-3075 | Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 19211 | CVE-2016-3402 | Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect confidentiality via unknown vectors, aka bug 99167. | 2 | 5 | Medium | 2017-02-06 | 2017-02-01 | View | |
| 19467 | CVE-2016-3688 | SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr. | 2 | 4 | Medium | 2017-01-19 | 2016-04-28 | View |
Page 2886 of 17672, showing 5 records out of 88360 total, starting on record 14426, ending on 14430