NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55174  CVE-2007-3017  The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp.    Medium  2017-01-07  2008-11-15  View
61318  CVE-2006-2633  Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users" directories by specifying the absolute path of the directory in the infolder parameter and simultaneously specifying the filename in the filepath parameter.    Medium  2016-12-20  2011-03-07  View
16775  CVE-2016-0323  The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.    Medium  2017-01-19  2016-05-19  View
20615  CVE-2016-5307  Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.    Medium  2017-01-19  2016-07-01  View
22919  CVE-2015-0441  Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Encryption.    Medium  2017-01-19  2017-01-02  View

Page 3129 of 17672, showing 5 records out of 88360 total, starting on record 15641, ending on 15645

Actions